PT-2021-15388 · Argo Cd · Argo Cd
Ezekiel Keator
+2
·
Published
2021-05-12
·
Updated
2024-08-07
·
CVE-2021-23135
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Argo CD versions 1.8.0 through 1.8.6
Argo CD versions 1.7.0 through 1.7.13
Description
The issue allows an attacker to cause leaked secret data into web UI error messages and logs due to exposure of system data to an unauthorized control sphere vulnerability in the web UI of Argo CD.
Recommendations
For Argo CD versions 1.8.0 through 1.8.6, update to version 1.8.7 or later.
For Argo CD versions 1.7.0 through 1.7.13, update to version 1.7.14 or later.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Argo Cd