Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

argoproj — Vulnerabilities & Security Advisories 62

Browse all 62 CVE security advisories affecting argoproj. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Argo Projects is an open-source cloud-native toolset primarily used for Kubernetes workflow orchestration and continuous delivery. Its core components, including Argo Workflows and Argo CD, facilitate complex pipeline automation and GitOps practices. Historically, the ecosystem has faced numerous security challenges, with records indicating approximately 56 Common Vulnerabilities and Exposures (CVEs). These issues predominantly involve privilege escalation, cross-site scripting (XSS), and remote code execution (RCE), often stemming from improper input validation or insufficient access controls within the web interfaces and API servers. While no single catastrophic incident has defined the project’s history, the high volume of vulnerabilities highlights the complexity of managing stateful applications in dynamic environments. Users are advised to maintain strict version control and apply security patches promptly to mitigate risks associated with these historically common vulnerability classes.

Found 42 results / 62Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2022-31102 Cross-site Scripting for Argo CD single sign on users — argo-cdCWE-79 2.6 Low2022-07-12
CVE-2022-31105 Argo CD's certificate verification is skipped for connections to OIDC providers — argo-cdCWE-295 8.3 High2022-07-12
CVE-2022-31036 Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server — argo-cdCWE-20 4.3 Medium2022-06-27
CVE-2022-31035 External URLs for Deployments can include javascript in argo-cd — argo-cdCWE-79 9.0 Critical2022-06-27
CVE-2022-31034 Insecure entropy in argo-cd — argo-cdCWE-330 8.3 High2022-06-27
CVE-2022-31016 Argo CD vulnerable to Uncontrolled Memory Consumption — argo-cdCWE-400 6.5 Medium2022-06-25
CVE-2022-29165 Argo CD will blindly trust JWT claims if anonymous access is enabled — argo-cdCWE-200 10.0 Critical2022-05-20
CVE-2022-24905 Argo CD login screen allows message spoofing if SSO is enabled — argo-cdCWE-20 4.3 Medium2022-05-20
CVE-2022-24904 Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server — argo-cdCWE-61 4.3 Medium2022-05-20
CVE-2022-24768 Improper access control allows admin privilege escalation in Argo CD — argo-cdCWE-200 9.9 Critical2022-03-23
CVE-2022-24731 Path traversal allows leaking out-of-bound files from Argo CD repo-server — argo-cdCWE-22 6.8 Medium2022-03-23
CVE-2022-24730 Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server — argo-cdCWE-22 7.7 High2022-03-23

This page lists every published CVE security advisory associated with argoproj. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.