Vulnerability index

Browse CVEs

64 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Argo Cd CRITICAL 9.1
CVE-2024-21662

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively by…

Fix: 2.8.13 / 2.9.9+
Fix from $2,300 2024-03-18
Argo Cd HIGH 7.5
CVE-2024-21661

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a crit…

Fix: 2.8.13 / 2.9.9+
Fix from $1,950 2024-03-18
Argo Cd CRITICAL 9.8
CVE-2024-21652

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chai…

Fix: 2.8.13 / 2.9.9+
Fix from $2,300 2024-03-18
Argo Cd MEDIUM 5.4
CVE-2024-28175

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link…

Fix: 2.8.12 / 2.9.8+
Fix from $1,600 2024-03-13
Argo Cd MEDIUM 6.4
CVE-2023-50726

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov…

Fix: 2.8.12 / 2.9.7+
Fix from $1,600 2024-03-13
Argo Cd HIGH 8.3
CVE-2024-22424

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vu…

Fix: 2.7.16 / 2.8.8+
Fix from $1,950 2024-01-19
Argo Cd MEDIUM 6.5
CVE-2023-40584

Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server comp…

Fix: 2.6.15 / 2.7.14+
Fix from $1,600 2023-09-07
Argo Cd CRITICAL 9.6
CVE-2023-40029

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. …

Fix: 2.6.15 / 2.7.14+
Fix from $2,300 2023-09-07
Argo Cd HIGH 7.1
CVE-2023-40025

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open w…

Fix: after 2.6.13
Fix from $1,950 2023-08-23
Argo Cd HIGH 8.5
CVE-2023-23947

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2…

Fix: 2.3.17 / 2.4.23+
Fix from $1,950 2023-02-16
Argo Cd MEDIUM 6.5
CVE-2023-25163

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitizatio…

Patch available
Fix from $1,600 2023-02-08
Argo Cd HIGH 8.5
CVE-2023-22736

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6…

Fix: 2.5.8+
Fix from $1,950 2023-01-26
Argo Cd HIGH 8.8
CVE-2023-22482

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6…

Fix: 2.3.14 / 2.4.20+
Fix from $1,950 2023-01-26
Argo Cd CRITICAL 9.6
CVE-2022-31105

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 i…

Fix: 2.2.11 / 2.3.6+
Fix from $2,300 2022-07-12
Argo Cd MEDIUM 6.1
CVE-2022-31102

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a…

Fix: 2.3.6 / 2.4.5+
Fix from $1,600 2022-07-12
Argo Cd HIGH 8.8
CVE-2022-1025

All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially esc…

Fix: after 2.3.1
Fix from $1,950 2022-07-12
Argo Cd HIGH 8.1
CVE-2022-31034

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety o…

Fix: 2.1.16+
Fix from $1,950 2022-06-27
Argo Cd MEDIUM 5.4
CVE-2022-31035

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site…

Fix: 2.1.16+
Fix from $1,600 2022-06-27
Argo Cd MEDIUM 6.5
CVE-2022-31016

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption…

Fix: 2.1.16 / 2.2.10+
Fix from $1,600 2022-06-25
Argo Cd CRITICAL 10.0
CVE-2022-29165

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with versi…

Fix: 2.1.15 / 2.2.9+
Fix from $2,300 2022-05-20
Argo Workflows HIGH 7.1
CVE-2022-29164

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can…

Fix: 3.2.11 / 3.3.5+
Fix from $1,950 2022-05-06
Argo Cd HIGH 8.8
CVE-2022-24768

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an …

Fix: 2.1.14 / 2.2.8+
Fix from $1,950 2022-03-23
Argo Cd MEDIUM 6.5
CVE-2022-24730

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and …

Fix: 2.1.11 / 2.2.6+
Fix from $1,600 2022-03-23
Argo Cd HIGH 7.7
CVE-2022-24348

Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. F…

Fix: 2.1.9 / 2.2.4+
Fix from $1,950 2022-02-04
Argo Workflows MEDIUM 6.5
CVE-2021-37914

In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflow…

Fix: after 3.1.3
Fix from $1,600 2021-08-03
Argo Cd MEDIUM 5.5
CVE-2021-23135

Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI …

Fix: 1.7.14 / 1.8.7+
Fix from $1,600 2021-05-12
Argo Cd HIGH 7.5
CVE-2021-26923

An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is …

Fix: 1.7.12 / 1.8.4+
Fix from $1,950 2021-03-15
Argo Cd MEDIUM 6.1
CVE-2021-26924

An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.

Fix: 1.7.12 / 1.8.4+
Fix from $1,600 2021-03-15
Argo Cd MEDIUM 6.5
CVE-2021-26921

In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

Fix: 1.7.12 / 1.8.4+
Fix from $1,600 2021-02-09
Argo Cd MEDIUM 6.5
CVE-2018-21034

In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which …

Fix: after 1.4.2
Fix from $1,600 2020-04-09