Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/argoproj/argo-cd/v2
  4. ›
  5. CVE-2022-24905

CVE-2022-24905: Improper Input Validation

May 24, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed. As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. There are currently no known workarounds.

References

  • github.com/advisories/GHSA-xmg8-99r8-jc2j
  • github.com/argoproj/argo-cd/releases/tag/v2.1.15
  • github.com/argoproj/argo-cd/releases/tag/v2.2.9
  • github.com/argoproj/argo-cd/releases/tag/v2.3.4
  • github.com/argoproj/argo-cd/security/advisories/GHSA-xmg8-99r8-jc2j
  • nvd.nist.gov/vuln/detail/CVE-2022-24905

Code Behaviors & Features

Detect and mitigate CVE-2022-24905 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.2.0 before 2.2.9, all versions starting from 2.3.0 before 2.3.4, all versions starting from 2.0.0 before 2.1.15

Fixed versions

  • v2.1.15
  • v2.2.9
  • v2.3.4

Solution

Upgrade to versions 2.1.15, 2.2.9, 2.3.4 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation

Source file

go/github.com/argoproj/argo-cd/v2/CVE-2022-24905.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:47 +0000.