Missing Authentication for Critical Function Affecting github.com/argoproj/argo-cd/v2/server/settings package, versions >=2.9.3 <2.9.17 >=2.10.0 <2.10.12 >=2.11.0 <2.11.3
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
16.29% (97th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDV2SERVERSETTINGS-7218837
- published 7 Jun 2024
- disclosed 6 Jun 2024
- credit moshikoHassan
Introduced: 6 Jun 2024
CVE-2024-37152 Open this link in a new tabHow to fix?
Upgrade github.com/argoproj/argo-cd/v2/server/settings
to version 2.9.17, 2.10.12, 2.11.3 or higher.
Overview
Affected versions of this package are vulnerable to Missing Authentication for Critical Function due to the exposure of the /api/v1/settings
endpoint. An attacker can access sensitive configuration data, including deployment settings and security configurations, by accessing this endpoint without authentication.
References
CVSS Scores
version 3.1