PT-2020-8679 · Argo · Argo

·

CVE-2018-21034

·

Published

2020-04-09

·

Updated

2024-08-20

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo versions prior to v1.5.0-rc1
Description The issue allows authenticated Argo users to submit API calls to retrieve secrets and other manifests stored within git.
Recommendations For versions prior to v1.5.0-rc1, update to version v1.5.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information stored within git until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21034
GHSA-XJ7V-C82W-92Q2
GO-2023-1952

Affected Products

Argo