Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39242
HistoryFeb 13, 2023 - 2:23 a.m.

Information Disclosure

2023-02-1302:23:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
argocd
information disclosure
error messages

EPSS

0.002

Percentile

55.1%

github.com/argoproj/argo-cd is vulnerable to Information Disclosure. The vulnerability exists because the repository_types.go does not properly sanitize the repo credentials in the error message, which allows an attacker to gain sensitive information through the user-facing error messages and logs.

EPSS

0.002

Percentile

55.1%