Skip to content

Unauthenticated Access to sensitive settings in Argo CD

Moderate
pasha-codefresh published GHSA-87p9-x75h-p4j2 Jun 6, 2024

Package

gomod argo-cd/server (Go)

Affected versions

v2.9.3+6eba5be

Patched versions

2.11.3, 2.10.12, 2.9.17

Description

Summary

The CVE allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication.

Details

Unauthenticated Access:

Endpoint: /api/v1/settings

Description: This endpoint is accessible without any form of authentication as expected. All sensitive settings are hidden except passwordPattern.

Patches
A patch for this vulnerability has been released in the following Argo CD versions:

v2.11.3
v2.10.12
v2.9.17

Impact

Unauthenticated Access:

  • Type: Unauthorized Information Disclosure.
  • Affected Parties: All users and administrators of the Argo CD instance.
  • Potential Risks: Exposure of sensitive configuration data, including but not limited to deployment settings, security configurations, and internal network information.

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2024-37152

Credits