Back

MEDIUM

Argo CD' API server does not enforce project sourceNamespaces

Published Apr 15, 2024

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 15, 2024
Updated Aug 2, 2024
Reserved Apr 8, 2024
CISA Vulnrichment
Updated Apr 23, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 15, 2024
ENISA EUVD
Assigner GitHub_M
Published Apr 15, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2024-1062 GHSA-2GVW-W6FJ-7M3C