Improper access control in Argo CD - CVE-2022-24768,CVE-2022-1025
Published: March 24, 2022
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper access restrictions. A remote authenticated user with push access to an Application's source git or Helm repository or sync</code> and <code>override access to an Application can gain administrative privileges.
Affected software
Red Hat OpenShift GitOps
How to mitigate CVE-2022-24768,CVE-2022-1025
Red Hat OpenShift GitOps - addressed in versions 1.2.3, 1.3.5, 1.3.6, 1.4.4