Argo CD是Argo开源的一个用于Kubernetes的声明性GitOps连续交付工具。 Argo CD 3.2.0至3.2.11之前版本和3.3.0至3.3.9之前版本存在信息泄露漏洞,该漏洞源于ServerSideDiff端点缺少授权和数据掩码,可能导致具有只读权限的攻击者通过Kubernetes API服务器的Server-Side Apply dry-run机制从etcd提取明文Kubernetes Secret数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: Extracted Kubernetes Secret via ArgoCD ServerSideDiff mechanism (CVE-2026-42880): password=S3cretP@ssw0rd!2024 username=admin
No comments yet