CVE-2025-23216

Aliases:GHSA-47g2-qmh2-749vBIT-argo-cd-2025-23216GO-2025-3433
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 30 Jan 2025, 15:30
Last modified:12 Feb 2025, 19:51

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.16% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jan 2025, 15:30
Published
Vulnerability first disclosed
12 Feb 2025, 19:51
Last Modified
Vulnerability information updated

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.

CVSS Metrics

  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.16% Percentile: 36%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-209Generation of Error Message Containing Sensitive Information

    The product generates an error message that includes sensitive information about its environment, users, or associated data.

Affected Systems

  • argoprojargo_cd

    < 2.11.13 | ≥ 2.12.0, < 2.12.10 | ≥ 2.13.0, < 2.13.4

  • argoprojargo-cd

    ≥ 2.13.0, < 2.13.4 | ≥ 2.12.0, < 2.12.10 | < 2.11.13

  • github.com/argoprojargo-cd

    ≤ 1.8.7 | all

  • github.com/argoproj/argo-cdv2

    ≥ 2.12.0, < 2.12.10 | < 2.11.13 | ≥ 2.13.0, < 2.13.4

References (6)