Vulnerability Description
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argoproj | Argo Cd | < 2.1.9 |
Related Weaknesses (CWE)
References
- https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-seExploitThird Party Advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7ExploitThird Party Advisory
- https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-seExploitThird Party Advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7ExploitThird Party Advisory
FAQ
What is CVE-2022-24348?
CVE-2022-24348 is a vulnerability with a CVSS score of 7.7 (HIGH). Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover cre...
How severe is CVE-2022-24348?
CVE-2022-24348 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24348?
Check the references section above for vendor advisories and patch information. Affected products include: Argoproj Argo Cd.