Lucene search

K
cve[email protected]CVE-2021-23135
HistoryMay 12, 2021 - 11:15 p.m.

CVE-2021-23135

2021-05-1223:15:07
CWE-209
CWE-497
web.nvd.nist.gov
39
7
cve-2021-23135
argo cd
web ui
vulnerability
data exposure
unauthorized control
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.

Affected configurations

NVD
Node
linuxfoundationargo_continuous_deliveryRange1.7.01.7.14kubernetes
OR
linuxfoundationargo_continuous_deliveryRange1.8.01.8.7kubernetes

CNA Affected

[
  {
    "product": "Argo CD",
    "vendor": "Argo CD",
    "versions": [
      {
        "lessThan": "1.8.7",
        "status": "affected",
        "version": "1.8",
        "versionType": "custom"
      },
      {
        "lessThan": "1.7.14",
        "status": "affected",
        "version": "1.7",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

Related for CVE-2021-23135