An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
| Software | From | Fixed in |
|---|---|---|
| linuxfoundation / argo-cd | 2.6.0 | 2.6.7 |
| linuxfoundation / argo-cd | 0.5.0 | 2.4.28 |
| linuxfoundation / argo-cd | 2.5.0 | 2.5.16 |
github.com/argoproj/argo-cd
|
0.5.0 | 1.8.7.x |
github.com/argoproj/argo-cd/v2
|
2.5.0 | 2.5.16 |
github.com/argoproj/argo-cd/v2
|
2.6.0 | 2.6.7 |
github.com/argoproj/argo-cd/v2
|
- | 2.4.28 |