CVE-2024-37152: Argoproj Argo Cd
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
Affected products
- Argoproj Argo Cd: from 2.9.3, before 2.9.17 (fixed in 2.9.17); from 2.10.0, before 2.10.12 (fixed in 2.10.12); from 2.11.0, before 2.11.3 (fixed in 2.11.3)
Published 2024-06-06. Last modified 2026-06-17.