CVE-2025-23216Medium· 6.8▾ SunlitArgo CD does not scrub secret values from patch errors
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository.
The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data.
A patch for this vulnerability is available in the following Argo CD versions:
There is no workaround other than upgrading.
Fixed with commit https://github.com/argoproj/argo-cd/commit/6f5537bdf15ddbaa0f27a1a678632ff0743e4107 & https://github.com/argoproj/gitops-engine/commit/7e21b91e9d0f64104c8a661f3f390c5e6d73ddca
github.com/argoproj/argo-cd/v2 >= 2.13.0, < 2.13.4github.com/argoproj/argo-cd/v2 >= 2.12.0, < 2.12.10github.com/argoproj/argo-cd/v2 < 2.11.13github.com/argoproj/argo-cd <= 1.8.7Upgrade to a patched release:
github.com/argoproj/argo-cd/v2 2.13.4github.com/argoproj/argo-cd/v2 2.12.10github.com/argoproj/argo-cd/v2 2.11.13Connected by shared product, vendor, weakness, or advisory.
GHSA-274v-mgcv-cm8jMedium· 6.8Argo CD GitOps Engine does not scrub secret values from patch errors
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow