CVE-2024-31990Medium· 4.8▾ SunlitArgo CD's API server does not enforce project sourceNamespaces
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
I can convince the UI to let me do things with an invalid Application.
p, michael, applications, *, demo/*, allow, where demo can just deploy to the demo namespacedev which reconciles from ns dev-appsp, michael, applications, sync, dev/*, allow, i.e. no updating via the UI allowed, gitops-onlypwn in dev-apps with project dev and sync the app with sources from gitA patch for this vulnerability has been released in the following Argo CD versions:
v2.10.7 v2.9.12 v2.8.16
If you have any questions or comments about this advisory:
Open an issue in the Argo CD issue tracker or discussions Join us on Slack in channel #argo-cd
This vulnerability was found & reported by @crenshaw-dev (Michael Crenshaw)
The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue
github.com/argoproj/argo-cd/v2 >= 2.4.0, < 2.8.16github.com/argoproj/argo-cd/v2 >= 2.9.0, < 2.9.12github.com/argoproj/argo-cd/v2 >= 2.10.0, < 2.10.7Upgrade to a patched release:
github.com/argoproj/argo-cd/v2 2.8.16github.com/argoproj/argo-cd/v2 2.9.12github.com/argoproj/argo-cd/v2 2.10.7Connected by shared product, vendor, weakness, or advisory.
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow