CVE-2025-23216

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
Configurations

No configuration.

History

30 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 16:15

Updated : 2025-01-30 16:15


NVD link : CVE-2025-23216

Mitre link : CVE-2025-23216

CVE.ORG link : CVE-2025-23216


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-209

Generation of Error Message Containing Sensitive Information