CVE-2024-21652

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 18, 2024
Updated: Jan 9, 2025
CWE ID 307

Summary

CVE-2024-21652 is a critical vulnerability affecting Argo CD, a popular Kubernetes continuous delivery tool, prior to versions 2.8.13, 2.9.9, and 2.10.4. An attacker can exploit a combination of a Denial of Service (DoS) flaw and in-memory data storage weakness to bypass Argo CD's brute force login protection, allowing them to crash the service and make unlimited login attempts. This significantly increases the risk of account compromise for all users. To mitigate this vulnerability, it is recommended that users upgrade to versions 2.8.13, 2.9.9, or 2.10.4, which contain the necessary patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share