Unauthenticated Access to sensitive settings in Argo CD
Package
Affected versions
>= 2.9.3, < 2.9.17
>= 2.10.0, < 2.10.12
>= 2.11.0, < 2.11.3
Patched versions
2.9.17
2.10.12
2.11.3
Description
Published by the National Vulnerability Database
Jun 6, 2024
Published to the GitHub Advisory Database
Jun 6, 2024
Reviewed
Jun 6, 2024
Last updated
Jun 17, 2024
Summary
The CVE allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication.
Details
Unauthenticated Access:
Endpoint: /api/v1/settings
Description: This endpoint is accessible without any form of authentication as expected. All sensitive settings are hidden except
passwordPattern
.Patches
A patch for this vulnerability has been released in the following Argo CD versions:
v2.11.3
v2.10.12
v2.9.17
Impact
Unauthenticated Access:
References