Database/Container, Kubernetes & orchestration
Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison
CVSS 9.0CVE-2024-31989Container, Kubernetes & orchestrationcurated
Impact
An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison the cache, which becomes arbitrary deployment
Who can reach it
Any pod on the cluster network
What to do
Rolling Argo CD upgrade; enable Redis auth and a NetworkPolicy around it. Critical in a multi-tenant neocloud where any tenant pod is on that network
References
Related entries
- Argo CD: Improper access control lets any user escalate to admin-levelCVE-2022-1025 · Argo CDHigh
- Argo CD: Authorization bypass lets an Application be synced to a destination it is not permitted to reachCVE-2023-22736 · Argo CDHigh
- Argo CD: Predictable SSO state values allow authentication bypass during loginCVE-2022-31034 · Argo CDHigh
- Argo CD: Improper certificate validation lets Argo CD be tricked into trusting a hostile endpointCVE-2022-31105 · Argo CDHigh
- Argo CD: CSRF against the Argo CD API allows deploying arbitrary workloads with Argo's cluster-admin rightsCVE-2024-22424 · Argo CDHigh
- Argo CD: Directory traversal via Helm charts discloses credentials from other Applications' value filesCVE-2022-24348 · Argo CDHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.