PT-2024-5351 · Argo Cd · Argo Cd

·

CVE-2024-37152

·

Published

2024-06-06

·

Updated

2024-09-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo CD versions prior to 2.11.3 Argo CD versions prior to 2.10.12 Argo CD versions prior to 2.9.17
Description The issue is related to insufficient authentication procedures when handling the "/api/v1/settings" endpoint, allowing unauthorized access to sensitive settings. All sensitive settings are hidden except passwordPattern. This could potentially expose sensitive configuration data, including deployment settings, security configurations, and internal network information.
Recommendations For versions prior to 2.11.3, update to version 2.11.3 or later. For versions prior to 2.10.12, update to version 2.10.12 or later. For versions prior to 2.9.17, update to version 2.9.17 or later. As a temporary workaround, consider restricting access to the "/api/v1/settings" endpoint until a patch is applied.

Exploit

Fix

DoS

Improper Authentication

Session Fixation

Missing Authentication

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2024-05984
BIT-ARGO-CD-2024-37152
CVE-2024-37152
GHSA-87P9-X75H-P4J2
GO-2024-2902

Affected Products

Argo Cd