cve/2024/CVE-2024-37152.md
2025-09-29 21:09:30 +02:00

1.5 KiB

CVE-2024-37152

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

POC

Reference

No PoCs from references.

Github