Home
HIGH: 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NDefault status
unaffected
3.2.0 (semver) before 3.2.11
affected
3.3.0 (semver) before 3.3.9
affected
Description
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
Problem types
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer
Product status
3.2.0 (semver) before 3.2.11
3.3.0 (semver) before 3.3.9
References
github.com/...rgo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3