CVE-2022-29165

CRITICAL10.0EPSS 1.6%

Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd

Published: 5/24/2022Modified: 3/3/2026

Description

Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References (6)