Database/Container, Kubernetes & orchestration
Argo CD: Improper authorization causes the API to accept tokens it should reject
CVSS 9.0CVE-2023-22482Container, Kubernetes & orchestrationcurated
Impact
Improper authorization causes the API to accept tokens it should reject
Who can reach it
Any authenticated Argo CD user
What to do
Rolling Argo CD upgrade
References
Related entries
- Argo CD: Improper URL protocol filtering in link annotations enables client-side attacks against adminsCVE-2024-28175 · Argo CDCritical
- Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poisonCVE-2024-31989 · Argo CDCritical
- Argo CD: Improper access control lets any user escalate to admin-levelCVE-2022-1025 · Argo CDHigh
- Argo CD: Authorization bypass lets an Application be synced to a destination it is not permitted to reachCVE-2023-22736 · Argo CDHigh
- Argo CD: Predictable SSO state values allow authentication bypass during loginCVE-2022-31034 · Argo CDHigh
- Argo CD: Improper certificate validation lets Argo CD be tricked into trusting a hostile endpointCVE-2022-31105 · Argo CDHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.