Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
The vulnerability results from improper filtering of URL protocols on the repository page in Argo CD. An attacker with repository editing permissions can inject a malicious XSS payload. When the victim visits the appropriate page, the payload executes in their browser and allows the attacker to send requests to the Argo CD API in the context of the victim's session. This enables the attacker to take control of actions performed by the victim in the application.
An attacker can perform arbitrary actions through the Argo CD API on behalf of a logged-in victim, potentially gaining access to sensitive configuration data, modifying Kubernetes resources, or escalating privileges in the GitOps environment.
Argo CD should be updated to version 2.13.8, 2.14.13, or 3.0.4, in which the vulnerability has been fixed. Additionally, it is recommended to restrict repository editing permissions exclusively to trusted users.
Argo CD in versions earlier than 2.13.8, 2.14.13, and 3.0.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HArgoproj Argo Cd
APPArgoproj1.2.01.2.1 – 2.13.8 (excl.)2.14.0 – 2.14.13 (excl.)3.0.0 – 3.0.4 (excl.)
Related vulnerabilities
Argo CD: ujawnienie danych Secret Kubernetes przez endpoint ServerSideDiff
Argo CD: nieuprawniony dostęp do poświadczeń repozytoriów przez API token
Argo CD: nieautoryzowany dostęp do Redis umożliwia privilege escalation
Argo CD: Ominięcie ochrony przed brute force logowania
Argo CD: XSS w adnotacjach linków umożliwia przejęcie uprawnień