Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
Vulnerability Description
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
不安全的默认资源初始化
Vulnerability Title
argoproj Argo Helm Charts 配置错误漏洞
Vulnerability Description
argoproj Argo Helm Charts是argoproj组织开源的一个由社区维护的 Helm Chart 集合,用于在 Kubernetes 上快速部署 Argo 项目。 argoproj Argo Helm Charts 10.0.0之前版本存在配置错误漏洞,该漏洞源于默认情况下未安装网络策略,允许集群中的任何 pod 访问 repo-server 和其他 Argo APIs。攻击者可通过组合攻击利用此不受限制的网络访问,实现集群破解和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A