Known vulnerabilities in Argo CD - page 3

Vendor: Argo
Software: Argo CD
Software CPE: cpe:2.3:a:argo:argo-cd:*:*:*:*:*:kubernetes:*:*
Total vulnerabilities: 68
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Argo CD Argo CD is affected by 68 known vulnerabilities: 6 high, 34 medium, 28 low Critical High Medium Low

Vulnerabilities (68)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129002 - Relative Path Traversal
CVE-2023-40026
CWE-23 Low
No
No
2.3.0 27.09.2023 SB2022030706
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
2.4.19 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more
#VU68385 - Security Features
CVE-2022-27665
CWE-254 Medium
No
No
2.3.10, 2.4.15 18.10.2022 SB2022101819
SB2022101821
SB2022101822
and 1 more
#VU66182 - Use After Free
CVE-2022-30065
CWE-416 High
No
No
2.2.12, 2.3.7, 2.4.8 08.08.2022 SB2022080820
SB2022080821
SB2022120201
and 8 more
#VU65367 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31102
CWE-79 Low
No
No
2.3.6, 2.4.5 15.07.2022 SB2022071515
#VU65366 - Improper Certificate Validation
CVE-2022-31105
CWE-295 High
No
No
2.2.11, 2.3.6, 2.4.5 15.07.2022 SB2022071515
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
2.2.12, 2.3.7, 2.4.8 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU64594 - Out-of-bounds write
CVE-2022-31036
CWE-787 Low
No
No
2.1.16, 2.2.10, 2.3.5, 2.4.1 22.06.2022 SB2022062239
SB2022062725
SB2022062727
and 2 more
#VU64593 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31035
CWE-79 Low
No
No
2.1.16, 2.2.10, 2.3.5, 2.4.1 22.06.2022 SB2022062239
SB2022062725
SB2022062727
and 2 more
#VU64591 - Resource exhaustion
CVE-2022-31016
CWE-400 Medium
No
No
2.1.16, 2.2.10, 2.3.5, 2.4.1 22.06.2022 SB2022062239
SB2022062725
SB2022062727
and 2 more
#VU64588 - Insufficient Entropy
CVE-2022-31034
CWE-331 High
No
No
2.1.16, 2.2.10, 2.3.5, 2.4.1 22.06.2022 SB2022062228
SB2022062239
SB2022062725
and 2 more
#VU64275 - Deserialization of Untrusted Data
CVE-2022-28948
CWE-502 Medium
No
No
2.2.12, 2.3.7, 2.4.8 14.06.2022 SB2022061420
SB2022061421
SB2022080821
and 15 more
#VU63413 - Authentication Bypass by Spoofing
CVE-2022-29165
CWE-290 High
No
No
2.1.15, 2.2.9, 2.3.4 19.05.2022 SB2022051901
#VU63412 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-24905
CWE-451 Low
No
No
2.1.15, 2.2.9, 2.3.4 19.05.2022 SB2022051901
#VU63411 - UNIX Symbolic Link (Symlink) Following
CVE-2022-24904
CWE-61 Low
No
No
2.1.15, 2.2.9, 2.3.4 19.05.2022 SB2022051901
#VU61587 - Improper Access Control
CVE-2022-1025
CWE-284 High
No
No
2.1.14, 2.2.8, 2.3.2 24.03.2022 SB2022032406
SB2022032444
SB2022032445
and 2 more
#VU61585 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-24731
CWE-22 Low
No
No
2.1.11, 2.2.6, 2.3.0 24.03.2022 SB2022032407
SB2022032444
SB2022032445
and 2 more
#VU61583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-24730
CWE-22 Medium
No
No
2.1.11, 2.2.6, 2.3.0 24.03.2022 SB2022032407
SB2022032444
SB2022032445
and 2 more
#VU61046 - Type confusion
CVE-2021-23820
CWE-843 High
No
No
2.2.12, 2.3.0 07.03.2022 SB2021110319
SB2022030706
SB2022060214
and 2 more
#VU60321 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-24348
CWE-22 Medium
Available
No
2.1.9, 2.2.4, 2.3.0 06.02.2022 SB2022020601
SB2022020935


Showing elements 41 - 60 out of 68