Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

argo-cd — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in argo-cd, with AI-generated Chinese analysis, references, and POCs.

This page details the Common Weakness Enumerations associated with the Argo CD product developed by the Argo project. It aggregates security data relevant to the continuous delivery platform, focusing on vulnerabilities identified within its architecture and deployment configurations. The collection spans from the product's inception to the present, capturing a comprehensive timeline of reported security issues, patches, and advisory notices. Readers can utilize this resource to track vendor advisories for Argo CD, allowing for timely assessment of risk exposure in their environments. Furthermore, the page facilitates a deeper understanding of specific weakness classes that frequently affect Kubernetes-native tools, helping security teams categorize threats by severity and impact. Users may also look up the product's vulnerability history to analyze trends in patching response times and the frequency of critical flaws over recent years. This historical context is essential for evaluating the long-term security posture of the tooling used in modern CI/CD pipelines. By consolidating these disparate data points, the page serves as a central reference for security analysts, DevOps engineers, and compliance officers who need to audit the safety of their Argo CD instances. The information provided is derived from official vendor disclosures and independent security research, ensuring accuracy and reliability for decision-making processes. This structured overview enables stakeholders to make informed choices regarding upgrades, mitigations, and alternative solutions when necessary.

Vendor: argoproj

CVE ID Title CVSS Severity Published
CVE-2023-22736 argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled CWE-862 8.6 High 2023-01-26
CVE-2023-22482 JWT audience claim is not verified CWE-863 9.1 Critical 2023-01-25
CVE-2022-31102 Cross-site Scripting for Argo CD single sign on users CWE-79 2.6 Low 2022-07-12
CVE-2022-31105 Argo CD's certificate verification is skipped for connections to OIDC providers CWE-295 8.3 High 2022-07-12
CVE-2022-31036 Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server CWE-20 4.3 Medium 2022-06-27
CVE-2022-31035 External URLs for Deployments can include javascript in argo-cd CWE-79 9.0 Critical 2022-06-27
CVE-2022-31034 Insecure entropy in argo-cd CWE-330 8.3 High 2022-06-27
CVE-2022-31016 Argo CD vulnerable to Uncontrolled Memory Consumption CWE-400 6.5 Medium 2022-06-25
CVE-2022-29165 Argo CD will blindly trust JWT claims if anonymous access is enabled CWE-200 10.0 Critical 2022-05-20
CVE-2022-24905 Argo CD login screen allows message spoofing if SSO is enabled CWE-20 4.3 Medium 2022-05-20
CVE-2022-24904 Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server CWE-61 4.3 Medium 2022-05-20
CVE-2022-24768 Improper access control allows admin privilege escalation in Argo CD CWE-200 9.9 Critical 2022-03-23
CVE-2022-24731 Path traversal allows leaking out-of-bound files from Argo CD repo-server CWE-22 6.8 Medium 2022-03-23
CVE-2022-24730 Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server CWE-22 7.7 High 2022-03-23

All 44 known CVE vulnerabilities affecting argo-cd with full Chinese analysis, references, and POCs where available.