CVE-2024-40634
CVSS V2 None
CVSS V3 None
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.
Overview
- CVE ID
- CVE-2024-40634
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-22T17:22:55.732Z
- Last Modified Date
- 2024-07-22T17:22:55.732Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/argoproj/argo-cd/security/advisories/GHSA-jmvp-698c-4x3w | x_refsource_CONFIRM |
https://github.com/argoproj/argo-cd/commit/46c0c0b64deaab1ece70cb701030b76668ad0cdc | x_refsource_MISC |
https://github.com/argoproj/argo-cd/commit/540e3a57b90eb3655db54793332fac86bcc38b36 | x_refsource_MISC |
https://github.com/argoproj/argo-cd/commit/d881ee78949e23160a0b280bb159e4d3d625a4df | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-40634 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40634 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-23 13:08:18 | Added to TrackCVE |