blob: 4e748deb4e54b8437dfb6431d951dc3b6c6539de [file] [log] [blame]
id: GO-2024-2728
modules:
- module: github.com/argoproj/argo-cd
vulnerable_at: 1.8.6
- module: github.com/argoproj/argo-cd/v2
versions:
- introduced: 2.4.0
- fixed: 2.8.16
- introduced: 2.9.0
- fixed: 2.9.12
- introduced: 2.10.0
- fixed: 2.10.7
vulnerable_at: 2.10.6
summary: Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd
cves:
- CVE-2024-31990
ghsas:
- GHSA-2gvw-w6fj-7m3c
references:
- advisory: https://github.com/argoproj/argo-cd/security/advisories/GHSA-2gvw-w6fj-7m3c
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-31990
- fix: https://github.com/argoproj/argo-cd/commit/c514105af739eebedb9dbe89d8a6dd8dfc30bb2c
- fix: https://github.com/argoproj/argo-cd/commit/c5a252c4cc260e240e2074794aedb861d07e9ca5
- fix: https://github.com/argoproj/argo-cd/commit/e0ff56d89fbd7d066e9c862b30337f6520f13f17
source:
id: GHSA-2gvw-w6fj-7m3c
created: 2024-08-16T16:27:22.05692-04:00
review_status: UNREVIEWED