MEDIUM
ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API
Published Mar 27, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.64%
Description
An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
Affected products
No data.
OR
- ≥ 0.5.0 · < 2.4.28
- ≥ 2.5.0 · < 2.5.16
- ≥ 2.6.0 · < 2.6.7
No data.
Red Hat OpenShift GitOps 1.6
openshift-gitops-1/argocd-rhel8:v1.6.6-1
Fixed · RHSA-2023:1453
Red Hat OpenShift GitOps 1.7
openshift-gitops-1/argocd-rhel8:v1.7.3-4
Fixed · RHSA-2023:1454
Red Hat OpenShift GitOps 1.8
openshift-gitops-1/argocd-rhel8:v1.8.1-1
Fixed · RHSA-2023:1452
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift GitOps 1.6 | openshift-gitops-1/argocd-rhel8:v1.6.6-1 | Fixed | RHSA-2023:1453 |
| Red Hat OpenShift GitOps 1.7 | openshift-gitops-1/argocd-rhel8:v1.7.3-4 | Fixed | RHSA-2023:1454 |
| Red Hat OpenShift GitOps 1.8 | openshift-gitops-1/argocd-rhel8:v1.8.1-1 | Fixed | RHSA-2023:1452 |
github.com/argoproj/argo-cd
Go
Introduced 0.5.0 Fixed not fixedgithub.com/argoproj/argo-cd/v2
Go
Introduced 2.5.0 Fixed 2.5.16github.com/argoproj/argo-cd/v2
Go
Introduced 2.6.0 Fixed 2.6.7github.com/argoproj/argo-cd/v2
Go
Introduced 0 Fixed 2.4.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/argoproj/argo-cd | 0.5.0 | not fixed |
| Go | github.com/argoproj/argo-cd/v2 | 2.5.0 | 2.5.16 |
| Go | github.com/argoproj/argo-cd/v2 | 2.6.0 | 2.6.7 |
| Go | github.com/argoproj/argo-cd/v2 | 0 | 2.4.28 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://argo.com
- https://access.redhat.com/security/cve/CVE-2022-41354 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2167820 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0830 Advisory
- https://github.com/advisories/GHSA-2q5c-qw9c-fmvq Advisory
- https://github.com/argoproj/argo-cd/commit/3a28c8a18cc2aa84fe81492625545d25c7a90bc3
- https://github.com/argoproj/argo-cd/releases/tag/v2.4.28
- https://github.com/argoproj/argo-cd/releases/tag/v2.5.16
- https://github.com/argoproj/argo-cd/releases/tag/v2.6.7
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-2q5c-qw9c-fmvq Vendor Advisory
- https://github.com/chunklhit/cve/blob/master/argo/argo-cd/application_enumeration.md Broken Link
- https://nvd.nist.gov/vuln/detail/CVE-2022-41354
- https://www.cve.org/CVERecord?id=CVE-2022-41354
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 27, 2023
Updated Jul 9, 2026
Reserved Sep 26, 2022
Link CVE-2022-41354
CISA Vulnrichment
Updated Feb 19, 2025
ENISA EUVD
EUVD-2023-0830 GHSA-2Q5C-QW9C-FMVQ Assigner mitre
Published Mar 27, 2023
Updated Jul 9, 2026
Exploited since n/a
Link EUVD-2023-0830