blob: 460b028b9f04ef2cf72673352237ab31083feea7 [file] [log] [blame]
id: GO-2023-1952
modules:
- module: github.com/argoproj/argo-cd
versions:
- fixed: 1.5.0-rc1
vulnerable_at: 1.4.3
summary: Argo Exposure of Sensitive Information in github.com/argoproj/argo-cd
cves:
- CVE-2018-21034
ghsas:
- GHSA-xj7v-c82w-92q2
references:
- advisory: https://github.com/advisories/GHSA-xj7v-c82w-92q2
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2018-21034
- fix: https://github.com/argoproj/argo-cd/commit/916d4aed5775fead4ab75f47c1d352cd0e73b815
- fix: https://github.com/argoproj/argo-cd/pull/3088
- report: https://github.com/argoproj/argo-cd/issues/470
- web: https://github.com/argoproj/argo-cd/blob/a1afe44066fcd0a0ab90a02a23177164bbad42cf/util/diff/diff.go#L399
source:
id: GHSA-xj7v-c82w-92q2
created: 2024-08-20T11:54:25.108822-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE