Vulnerability Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed. As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. There are currently no known workarounds.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argoproj | Argo Cd | >= 0.6.1, < 2.1.15 |
Related Weaknesses (CWE)
References
- https://github.com/argoproj/argo-cd/releases/tag/v2.1.15Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/releases/tag/v2.2.9Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/releases/tag/v2.3.4Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-xmg8-99r8-jc2jThird Party Advisory
- https://github.com/argoproj/argo-cd/releases/tag/v2.1.15Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/releases/tag/v2.2.9Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/releases/tag/v2.3.4Release NotesThird Party Advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-xmg8-99r8-jc2jThird Party Advisory
FAQ
What is CVE-2022-24905?
CVE-2022-24905 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error message...
How severe is CVE-2022-24905?
CVE-2022-24905 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24905?
Check the references section above for vendor advisories and patch information. Affected products include: Argoproj Argo Cd.