QID 995427
Date Published: 2023-10-03
QID 995427: GO (Go) Security Update for github.com/argoproj/argo-cd (GHSA-6jqw-jwf5-rp8h)
In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external Helm charts handled by the same repo-server to leak values, or files from the referenced Helm Chart. This was possible because Helm paths were predictable.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6jqw-jwf5-rp8h for updates and patch information.
Vendor References
- GHSA-6jqw-jwf5-rp8h -
github.com/advisories/GHSA-6jqw-jwf5-rp8h
CVEs related to QID 995427
Software Advisories
| Advisory ID | Software | Component | Link |
|---|