QID 995427

Date Published: 2023-10-03

QID 995427: GO (Go) Security Update for github.com/argoproj/argo-cd (GHSA-6jqw-jwf5-rp8h)

In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external Helm charts handled by the same repo-server to leak values, or files from the referenced Helm Chart. This was possible because Helm paths were predictable.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-6jqw-jwf5-rp8h for updates and patch information.
    Vendor References

    CVEs related to QID 995427

    Software Advisories
    Advisory ID Software Component Link