CVE-2024-32476
CVSS V2 None
CVSS V3 None
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
Overview
- CVE ID
- CVE-2024-32476
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-26T15:24:13.245Z
- Last Modified Date
- 2024-06-04T17:50:51.120Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq | x_refsource_CONFIRM |
https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657 | x_refsource_MISC |
https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5a | x_refsource_MISC |
https://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cac | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-32476 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-32476 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 08:38:54 | Added to TrackCVE |