Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

argo-cd — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in argo-cd, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data specifically for Argo CD, a continuous delivery tool, with a primary focus on Cross-Site Scripting (CWE-79) weaknesses. The collection compiles historical security advisories issued by the Argo CD project, covering all known Cross-Site Scripting incidents documented in the repository. Readers can use this aggregation to track the vendor’s advisory history, understand the prevalence of the Cross-Site Scripting weakness class in this product, and review the complete vulnerability timeline without navigating individual database entries. The dataset spans the period during which Argo CD security teams actively patched these specific defects, providing a consolidated view of how the product has mitigated scripting injection risks over time. No specific CVE identifiers are listed; instead, the focus remains on the pattern and frequency of this particular weakness type within the Argo CD ecosystem. This view supports security teams in assessing the product’s historical exposure to client-side scripting vulnerabilities.

Vendor: argoproj

CVE ID Title CVSS Severity Published
CVE-2023-25163 Argo CD leaks repository credentials in user-facing error messages and in logs CWE-532 6.3 Medium 2023-02-08
CVE-2023-22736 argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled CWE-862 8.6 High 2023-01-26
CVE-2023-22482 JWT audience claim is not verified CWE-863 9.1 Critical 2023-01-25
CVE-2022-31102 Cross-site Scripting for Argo CD single sign on users CWE-79 2.6 Low 2022-07-12
CVE-2022-31105 Argo CD's certificate verification is skipped for connections to OIDC providers CWE-295 8.3 High 2022-07-12
CVE-2022-31036 Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server CWE-20 4.3 Medium 2022-06-27
CVE-2022-31035 External URLs for Deployments can include javascript in argo-cd CWE-79 9.0 Critical 2022-06-27
CVE-2022-31034 Insecure entropy in argo-cd CWE-330 8.3 High 2022-06-27
CVE-2022-31016 Argo CD vulnerable to Uncontrolled Memory Consumption CWE-400 6.5 Medium 2022-06-25
CVE-2022-29165 Argo CD will blindly trust JWT claims if anonymous access is enabled CWE-200 10.0 Critical 2022-05-20
CVE-2022-24905 Argo CD login screen allows message spoofing if SSO is enabled CWE-20 4.3 Medium 2022-05-20
CVE-2022-24904 Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server CWE-61 4.3 Medium 2022-05-20
CVE-2022-24768 Improper access control allows admin privilege escalation in Argo CD CWE-200 9.9 Critical 2022-03-23
CVE-2022-24731 Path traversal allows leaking out-of-bound files from Argo CD repo-server CWE-22 6.8 Medium 2022-03-23
CVE-2022-24730 Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server CWE-22 7.7 High 2022-03-23

All 45 known CVE vulnerabilities affecting argo-cd with full Chinese analysis, references, and POCs where available.