Логотип exploitDog
bind:CVE-2025-23216
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-23216

Количество 4

Количество 4

redhat логотип

CVE-2025-23216

8 месяцев назад

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-23216

8 месяцев назад

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-47g2-qmh2-749v

8 месяцев назад

Argo CD does not scrub secret values from patch errors

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0429-1

7 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-23216

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS3: 6.8
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-23216

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS3: 6.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-47g2-qmh2-749v

Argo CD does not scrub secret values from patch errors

CVSS3: 6.8
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0429-1

Security update for govulncheck-vulndb

7 месяцев назад

Уязвимостей на страницу