Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the token has already expired. The most straightforward scenario is when a user opens the terminal view and leaves it open for an extended period. This allows the user to view sensitive information even when they should have been logged out already. A patch for this vulnerability has been released in the following Argo CD versions: 2.6.14, 2.7.12 and 2.8.1.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:18
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
References | () https://github.com/argoproj/argo-cd/commit/e047efa8f9518c54d00d2e4493b64bc4dba98478 - Patch | |
References | () https://github.com/argoproj/argo-cd/security/advisories/GHSA-c8xw-vjgf-94hr - Exploit, Vendor Advisory |
07 Aug 2024, 15:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:linuxfoundation:argo-cd:2.7.11:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:argo-cd:2.8.0:*:*:*:*:*:*:* |
cpe:2.3:a:argoproj:argo_cd:2.7.11:*:*:*:*:*:*:* cpe:2.3:a:argoproj:argo_cd:2.8.0:*:*:*:*:*:*:* cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
First Time |
Argoproj
Argoproj argo Cd |
30 Aug 2023, 17:28
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:linuxfoundation:argo-cd:2.7.11:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:argo-cd:*:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:argo-cd:2.8.0:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
References | (MISC) https://github.com/argoproj/argo-cd/commit/e047efa8f9518c54d00d2e4493b64bc4dba98478 - Patch | |
References | (MISC) https://github.com/argoproj/argo-cd/security/advisories/GHSA-c8xw-vjgf-94hr - Exploit, Vendor Advisory | |
First Time |
Linuxfoundation
Linuxfoundation argo-cd |
23 Aug 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-23 20:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-40025
Mitre link : CVE-2023-40025
CVE.ORG link : CVE-2023-40025
JSON object : View
Products Affected
argoproj
- argo_cd
CWE
CWE-613
Insufficient Session Expiration