Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/argoproj/argo-cd/v2/server(Go) | 2.9.3 | 2.9.17 | N/A |
| github.com/argoproj/argo-cd/v2/server(Go) | 2.10.0 | 2.10.12 | N/A |
| github.com/argoproj/argo-cd/v2/server(Go) | 2.11.0 | 2.11.3 | N/A |
CVSS Metrics