Database/Container, Kubernetes & orchestration
Argo CD: Unauthenticated attackers can enumerate existing applications
CVE-2022-41354Container, Kubernetes & orchestrationcurated
Impact
Unauthenticated attackers can enumerate existing applications
Who can reach it
Unauthenticated network reaching the Argo CD API
What to do
Rolling Argo CD upgrade; put the API behind auth
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.