PT-2023-1394 · Argo Cd · Argo Cd

Crenshaw-Dev

·

Published

2023-02-03

·

Updated

2024-08-07

·

CVE-2023-25163

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo CD versions 2.6.0-rc1 through 2.6.0
Description The issue is related to an output sanitization bug in Argo CD, which leaks repository access credentials in error messages. These error messages are visible to the user and are logged. The error message is visible when a user attempts to create or update an Application via the Argo CD API. The user must have applications, create or applications, update RBAC access to reach the code that may produce the error.
Recommendations For versions 2.6.0-rc1 through 2.6.0, upgrade to version 2.6.1 to resolve the issue. To mitigate the issue, ensure that your repository credentials have only the least necessary privileges. Enable commit signature verification to prevent malicious commits from being synced. Enforce least privileges in Argo CD RBAC, ensuring users only have repositories, update, applications, update, or applications, create access if they absolutely need it.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00763
BIT-ARGO-CD-2023-25163
CVE-2023-25163
GHSA-MV6W-J4XC-QPFW
GO-2023-1548

Affected Products

Argo Cd