#VU53661 Improper Authorization in Red Hat OpenShift GitOps - CVE-2021-3557
Published: May 30, 2021
Red Hat OpenShift GitOps
Red Hat Inc.
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists in the argo-cd implementation. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations.