PT-2024-5351 · Argo Cd · Argo Cd

Moshikohassan

·

Published

2024-06-06

·

Updated

2024-09-18

·

CVE-2024-37152

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo CD versions prior to 2.11.3 Argo CD versions prior to 2.10.12 Argo CD versions prior to 2.9.17
Description The issue is related to insufficient authentication procedures when handling the "/api/v1/settings" endpoint, allowing unauthorized access to sensitive settings. All sensitive settings are hidden except passwordPattern. This could potentially expose sensitive configuration data, including deployment settings, security configurations, and internal network information.
Recommendations For versions prior to 2.11.3, update to version 2.11.3 or later. For versions prior to 2.10.12, update to version 2.10.12 or later. For versions prior to 2.9.17, update to version 2.9.17 or later. As a temporary workaround, consider restricting access to the "/api/v1/settings" endpoint until a patch is applied.

Exploit

Fix

Session Fixation

Path traversal

Improper Authentication

RCE

Missing Authentication

Related Identifiers

BDU:2024-05984
BIT-ARGO-CD-2024-37152
CVE-2024-37152
GHSA-87P9-X75H-P4J2
GO-2024-2902

Affected Products

Argo Cd