CVE-2024-37152

MEDIUM5.3EPSS 80.2%

Unauthenticated Access to sensitive settings in Argo CD

發布日:2024/6/6修改日:2025/5/20
也稱為:GHSA-87p9-x75h-p4j2BIT-argo-cd-2024-37152GO-2024-2902

描述

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

參考連結(5)