CVE-2025-23216

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Jan 30, 2025
CWE ID 209
CWE ID 200

Summary

CVE-2025-23216 is a vulnerability affecting Argo CD, a GitOps continuous delivery tool for Kubernetes. The issue exposes secret values in error messages and the diff view when an invalid Kubernetes Secret resource is synced. Exploitation requires write access to the repository, which can be exploited intentionally or unintentionally by committing an invalid Secret. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability has been addressed in versions v2.13.4, v2.12.10, and v2.11.13.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share