Security features bypass in Argo CD - CVE-2024-21652
Published: April 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass brute-force protection.
The vulnerability exists due to an error when handling different application states. A remote attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection.
Affected software
Red Hat OpenShift GitOps
microshift-gitops (Red Hat package)
openshift-gitops-argocd-cli (Red Hat package)
How to mitigate CVE-2024-21652
Red Hat OpenShift GitOps - addressed in versions 1.10.4, 1.11.3, 1.12.1
microshift-gitops (Red Hat package) - update to 1.12.1-4.el9
openshift-gitops-argocd-cli (Red Hat package) - addressed in versions 1.12.1-4.el9, 1.12.1-5.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Argo CD
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps v1.12.1 for Argo CD CLI and MicroShift GitOps