PT-2024-5351 · Argo Cd · Argo Cd
Moshikohassan
·
Published
2024-06-06
·
Updated
2024-09-18
·
CVE-2024-37152
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Argo CD versions prior to 2.11.3
Argo CD versions prior to 2.10.12
Argo CD versions prior to 2.9.17
Description
The issue is related to insufficient authentication procedures when handling the "/api/v1/settings" endpoint, allowing unauthorized access to sensitive settings. All sensitive settings are hidden except
passwordPattern. This could potentially expose sensitive configuration data, including deployment settings, security configurations, and internal network information.Recommendations
For versions prior to 2.11.3, update to version 2.11.3 or later.
For versions prior to 2.10.12, update to version 2.10.12 or later.
For versions prior to 2.9.17, update to version 2.9.17 or later.
As a temporary workaround, consider restricting access to the "/api/v1/settings" endpoint until a patch is applied.
Exploit
Fix
Session Fixation
Path traversal
Improper Authentication
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Argo Cd