Dismissed
(no matching packages found)
Permalink
CVE-2026-45737
6.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created & dismissed (no matching packages found) suggestion
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because HideSecretData(target, live, ...) does not fully sanitize ResourceDiff.TargetState and LiveState predicted live Secret objects, allowing sensitive data, stringData, and annotations to appear in UI or CLI diffs. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.
References
-
https://github.com/argoproj/argo-cd/security/advisories/GHSA-rg3g-4rw9-gqrp x_refsource_CONFIRM
-
https://github.com/argoproj/argo-cd/releases/tag/v3.2.12 x_refsource_MISC
-
https://github.com/argoproj/argo-cd/releases/tag/v3.3.10 x_refsource_MISC
-
https://github.com/argoproj/argo-cd/releases/tag/v3.4.2 x_refsource_MISC
Affected products
argo-cd
- ==>= 3.2.0, < 3.2.12
- ==>= 3.3.9, < 3.3.10
- ==>= 3.4.1, < 3.4.2