CVE-2025-23216

Aliases:GHSA-47g2-qmh2-749vBIT-argo-cd-2025-23216GO-2025-3433CGA-7x8h-m3j6-h99mCGA-8xpg-crgv-7xxvCGA-gh72-f236-j4rjCGA-4ww7-mcwq-wmjhCGA-767q-v82x-84pvCGA-cx5r-w58h-w4jvCGA-g9m9-f6jq-x65vCGA-j76f-vhqj-4g74CGA-jh5c-rgww-cwp7CGA-m8v7-vcvh-cfxcCGA-r3r3-6x83-44qvCGA-r7v7-3wc8-phfwCGA-r8cj-q622-9mxfCGA-x253-7969-p24j
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 30 Jan 2025, 15:30
Last modified:12 Feb 2025, 19:51

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.47% LOW
0% probability +0.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jan 2025, 15:30
Published
Vulnerability first disclosed
12 Feb 2025, 19:51
Last Modified
Vulnerability information updated

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS Metrics

  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-209Generation of Error Message Containing Sensitive Information

    The product generates an error message that includes sensitive information about its environment, users, or associated data.

Affected Systems

  • chainguardargo-cd-2.11

    < 0

  • chainguardargo-cd-2.13

    < 0

  • chainguardargo-cd-2.14

    < 0

  • chainguardargo-cd-fips-2.14

    < 0

  • chainguardargocd-image-updater

    < 0.15.2-r3

  • chainguardargocd-image-updater-compat

    < 0.15.2-r3

  • chainguardargocd-image-updater-fips

    < 0.15.2-r2

  • wolfiargocd-image-updater

    < 0.15.2-r3

  • wolfiargocd-image-updater-compat

    < 0.15.2-r3

  • argoprojargo_cd

    < 2.11.13 | ≥ 2.12.0, < 2.12.10 | ≥ 2.13.0, < 2.13.4

  • argoprojargo-cd

    ≥ 2.13.0, < 2.13.4 | ≥ 2.12.0, < 2.12.10 | < 2.11.13

  • github.com/argoprojargo-cd

    all | ≤ 1.8.7

  • github.com/argoproj/argo-cdv2

    ≥ 2.13.0, < 2.13.4 | ≥ 2.12.0, < 2.12.10 | < 2.11.13

References (7)