CVE-2024-31990
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Apr 15, 2024
Updated: Apr 16, 2024
CWE ID 863
Summary
CVE-2024-31990: Argo CD's API server fails to enforce project sourceNamespaces, allowing unauthorized users to edit resources through the UI instead of via GitOps. This vulnerability affects Argo CD versions prior to 2.10.7, 2.9.12, and 2.8.16. Attackers can exploit this issue to manipulate Kubernetes resources, leading to potential security risks. It is recommended to update Argo CD to a patched version as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share