Information Exposure Affecting github.com/argoproj/argo-cd/util/exec package, versions >=1.7.0 <1.7.14 >=1.8.0 <1.8.7
Do your applications use this vulnerable package?
- Snyk ID SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDUTILEXEC-1292155
- published 13 May 2021
- disclosed 13 May 2021
- credit Ezekiel Keator and and Kevin Haung of Palo Alto Networks
How to fix?
github.com/argoproj/argo-cd/util/exec to version 1.7.14, 1.8.7 or higher.
github.com/argoproj/argo-cd/util/exec is an Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
Affected versions of this package are vulnerable to Information Exposure. Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs.This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.