Argo CD is a declarative, GitOps... CVE-2024-37152

- AV AC AU C I A
发布: 2024-06-06
修订: 2024-09-18

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

0%
暂无可用Exp或PoC
当前有3条受影响产品信息