PT-2025-4855 · Argo Cd +1 · Argo Cd +1
Jannfis
+1
·
Published
2025-01-30
·
Updated
2025-06-06
·
CVE-2025-23216
6.8
Medium
Base vector | Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Argo CD versions prior to v2.13.4
Argo CD versions prior to v2.12.10
Argo CD versions prior to v2.11.13
Description:
A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data.
Recommendations:
For versions prior to v2.13.4, update to v2.13.4 or later to fix the vulnerability.
For versions prior to v2.12.10, update to v2.12.10 or later to fix the vulnerability.
For versions prior to v2.11.13, update to v2.11.13 or later to fix the vulnerability.
As a temporary workaround is not available, upgrading to the specified versions is the recommended course of action.
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Related Identifiers
Affected Products
References · 88
- https://github.com/argoproj/argo-cd/commit/6f5537bdf15ddbaa0f27a1a678632ff0743e4107⭐ 19755 🔗 6058 · Patch
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-47g2-qmh2-749v⭐ 19755 🔗 6058 · Patch
- https://github.com/argoproj/gitops-engine/commit/7e21b91e9d0f64104c8a661f3f390c5e6d73ddca⭐ 1755 🔗 282 · Patch
- https://osv.dev/vulnerability/SUSE-SU-2025:0429-1 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-03456 · Security Note
- https://bdu.fstec.ru/vul/2025-06412 · Security Note
- https://bdu.fstec.ru/vul/2025-02667 · Security Note
- https://osv.dev/vulnerability/GHSA-47g2-qmh2-749v · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-01439 · Security Note
- https://bdu.fstec.ru/vul/2025-02447 · Security Note
- https://osv.dev/vulnerability/CVE-2025-23216 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-02456 · Security Note
- https://bdu.fstec.ru/vul/2025-02454 · Security Note
- https://bdu.fstec.ru/vul/2025-02785 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-23216 · Security Note