#VU63413 Authentication Bypass by Spoofing in Argo CD - CVE-2022-29165
Published: May 19, 2022 / Updated: May 19, 2022
Argo CD
Argo
Description
The vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can send a specifically crafted JSON Web Token (JWT) along with the request and impersonate any Argo CD user or role, including the admin user.
Successful exploitation of the vulnerability requires that anonymous access to the Argo CD instance is enabled.