Database/Container, Kubernetes & orchestration
Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison
CVE-2024-31989Container, Kubernetes & orchestrationcurated
Impact
An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison the cache, which becomes arbitrary deployment
Who can reach it
Any pod on the cluster network
What to do
Rolling Argo CD upgrade; enable Redis auth and a NetworkPolicy around it. Critical in a multi-tenant neocloud where any tenant pod is on that network
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.