HIGHGo →
Argo CD's API server does not enforce project sourceNamespaces
Argo CD's API server does not enforce project sourceNamespaces
Affected packages
- github.com/argoproj/argo-cd/v2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-2gvw-w6fj-7m3c
- https://nvd.nist.gov/vuln/detail/CVE-2024-31990
- https://github.com/argoproj/argo-cd/commit/c514105af739eebedb9dbe89d8a6dd8dfc30bb2c
- https://github.com/argoproj/argo-cd/commit/c5a252c4cc260e240e2074794aedb861d07e9ca5
- https://github.com/argoproj/argo-cd/commit/e0ff56d89fbd7d066e9c862b30337f6520f13f17
- https://github.com/argoproj/argo-cd
Structured record: https://osv.dev/vulnerability/GHSA-2gvw-w6fj-7m3c
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta