Vulnerabilities
Last updated 7 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL | High Risk 8.8 | 4 hours ago | 4 hours ago |
|
|
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation | High Risk 7.3 | 4 months ago | 29 days ago |
|
|
Argo CD's Project API Token Exposes Repository Credentials | Critical 9.9 | 1 year ago | 29 days ago |
|
|
Argo CD does not scrub secret values from patch errors | Medium Risk 6.8 | 1 year ago | 29 days ago |
|
|
Unauthenticated Access to sensitive settings in Argo CD | Medium Risk 5.3 | 2 years ago | 29 days ago |
|
|
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment | High Risk 7.5 | 2 years ago | 29 days ago |
|
|
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability | High Risk 8.3 | 2 years ago | 29 days ago |
|
|
Argo CD leaks repository credentials in user-facing error messages and in logs | Medium Risk 6.3 | 3 years ago | 29 days ago |
|
|
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server | Medium Risk 5.0 | 3 years ago | 29 days ago |
|
|
Controller reconciles apps outside configured namespaces when sharding is enabled | High Risk 8.5 | 3 years ago | 29 days ago |
|
|
Argo CD allows cross-site scripting on repositories page | Critical 9.0 | 1 year ago | 29 days ago |
|
|
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache | Critical 9.0 | 2 years ago | 29 days ago |
|
|
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint | High Risk 7.5 | 2 years ago | 29 days ago |
|
|
Repository Credentials Race Condition Crashes Argo CD Server | Medium Risk 6.5 | 1 year ago | 1 month ago |
|
|
Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd | Unknown | 11 months ago | 1 month ago |
|
|
Argo CD's API server does not enforce project sourceNamespaces | Medium Risk 4.8 | 2 years ago | 2 months ago |
|
|
The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd | Unknown | 2 years ago | 2 months ago |
|
|
Users with `create` but not `override` privileges can perform local sync | Medium Risk 6.4 | 2 years ago | 2 months ago |
|
|
Cross-site scripting on application summary component | Critical 9.0 | 2 years ago | 2 months ago |
|
|
Out of memory crash from malicious Helm registry in github.com/argoproj/argo-cd/v2 | Unknown | 2 years ago | 2 months ago |
|
|
Bypassing Rate Limit and Brute Force Protection Using Cache Overflow | Medium Risk 5.4 | 2 years ago | 2 months ago |
|
|
Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss | Critical 9.8 | 2 years ago | 2 months ago |
|
|
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences | Medium Risk 6.5 | 2 years ago | 2 months ago |
|
|
Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 | Unknown | 2 years ago | 2 months ago |
|
|
The Argo CD web terminal session does not handle the revocation of user permissions properly | Medium Risk 4.7 | 2 years ago | 2 months ago |
|
|
Brute force protection bypass in github.com/argoproj/argo-cd/v2 | Unknown | 2 years ago | 2 months ago |
|
|
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd | Unknown | 2 years ago | 2 months ago |
|
|
Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd | Unknown | 2 years ago | 2 months ago |
|
|
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability | Medium Risk 6.5 | 2 years ago | 2 months ago |
|
|
Bypass manifest during application creation in github.com/argoproj/argo-cd/v2 | Unknown | 2 years ago | 2 months ago |
|
|
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd | Unknown | 3 months ago | 2 months ago |
|
|
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations in github.com/argoproj/argo-cd | Unknown | 3 months ago | 2 months ago |
|
|
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd | Unknown | 3 months ago | 3 months ago |
|
|
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2 | Medium Risk 4.7 | 5 years ago | 3 months ago |
|
|
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level | High Risk 8.8 | 4 years ago | 3 months ago |
|
|
Improper access control allows admin privilege escalation in Argo CD in github.com/argoproj/argo-cd | Unknown | 2 years ago | 3 months ago |
|
|
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level in github.com/argoproj/argo-cd | Unknown | 2 years ago | 3 months ago |
|
|
Path traversal and dereference of symlinks in Argo CD | High Risk 7.7 | 4 years ago | 3 months ago |
|
|
Argo CD authenticated but unauthorized users may enumerate Application names via the API | Medium Risk 5.3 | 3 years ago | 3 months ago |
|
|
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd | Unknown | 11 months ago | 5 months ago |
|
|
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd | Unknown | 11 months ago | 5 months ago |
|
|
Unauthenticated Access to sensitive settings in Argo CD in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Argo CD cluster secret might leak in cluster details page in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Argo CD repo-server Denial of Service vulnerability in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Users with any cluster secret update access may update out-of-bounds cluster secrets in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Controller reconciles apps outside configured namespaces when sharding is enabled in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
JWT audience claim is not verified in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
|
|
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd | Unknown | 2 years ago | 7 months ago |
Page 1