PT-2021-15388 · Argo Cd · Argo Cd

Ezekiel Keator

+2

·

Published

2021-05-12

·

Updated

2024-08-07

·

CVE-2021-23135

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo CD versions 1.8.0 through 1.8.6 Argo CD versions 1.7.0 through 1.7.13
Description The issue allows an attacker to cause leaked secret data into web UI error messages and logs due to exposure of system data to an unauthorized control sphere vulnerability in the web UI of Argo CD.
Recommendations For Argo CD versions 1.8.0 through 1.8.6, update to version 1.8.7 or later. For Argo CD versions 1.7.0 through 1.7.13, update to version 1.7.14 or later.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BIT-ARGO-CD-2021-23135
CVE-2021-23135
GHSA-FP89-H8PJ-8894

Affected Products

Argo Cd