GPU VulnDB

Database/Container, Kubernetes & orchestration

Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison

CVE-2024-31989Container, Kubernetes & orchestrationcurated

Impact

An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poison the cache, which becomes arbitrary deployment

Who can reach it

Any pod on the cluster network

What to do

Rolling Argo CD upgrade; enable Redis auth and a NetworkPolicy around it. Critical in a multi-tenant neocloud where any tenant pod is on that network

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.