PT-2025-5629 · Argo Cd · Argo Cd

Published

2025-01-30

·

Updated

2025-01-30

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Argo CD versions prior to 2.13.4 Argo CD versions prior to 2.12.10 Argo CD versions prior to 2.11.13
Description: A vulnerability was discovered that exposes secret values in error messages and the diff view when an invalid Kubernetes Secret resource is synced from a repository. This issue can be exploited by a user with write access to the repository, who can commit an invalid Secret and trigger a Sync, intentionally or unintentionally. Once exploited, any user with read access to Argo CD can view the exposed secret data.
Recommendations: For versions prior to 2.13.4, update to version 2.13.4 or later. For versions prior to 2.12.10, update to version 2.12.10 or later. For versions prior to 2.11.13, update to version 2.11.13 or later.

Fix

Related Identifiers

GHSA-274V-MGCV-CM8J

Affected Products

Argo Cd