Use of a broken or risky cryptographic algorithm in Argo CD - CVE-2024-31989
Published: May 21, 2024 / Updated: May 2, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary deployments and disclose sensitive information.
The vulnerability exists due to use of risky or missing cryptographic algorithms in redis cache entries when processing data read from the redis cache. A remote user can modify the "mfst" or "app|resources-tree" keys to execute arbitrary deployments and disclose sensitive information.
Exploitation requires access to the Redis server on the local network segment, such as from another pod in the same cluster.
Affected software
Red Hat OpenShift GitOps
How to mitigate CVE-2024-31989
Red Hat OpenShift GitOps - addressed in versions 1.10.6, 1.11.5, 1.12.3