Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
| Software | From | Fixed in |
|---|---|---|
github.com/argoproj/argo-cd/v2/server
|
2.9.3 | 2.9.17 |
github.com/argoproj/argo-cd/v2/server
|
2.10.0 | 2.10.12 |
github.com/argoproj/argo-cd/v2/server
|
2.11.0 | 2.11.3 |
| argoproj / argo_cd | 2.11.0 | 2.11.3 |
| argoproj / argo_cd | 2.10.0 | 2.10.12 |
| argoproj / argo_cd | 2.9.3 | 2.9.17 |