Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2379 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20. |
Github GHSA |
GHSA-jmvp-698c-4x3w | Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint |
References
History
Thu, 09 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj argo Cd
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Argoproj argo Cd
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:33:11.910Z
Reserved: 2024-07-08T16:13:15.511Z
Link: CVE-2024-40634
Updated: 2024-07-23T13:15:22.204Z
Status : Analyzed
Published: 2024-07-22T18:15:03.770
Modified: 2025-01-09T16:55:20.183
Link: CVE-2024-40634
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA