Related Vulnerabilities: CVE-2022-24731  

A path traversal flaw was found in ArgoCD. This flaw allows an attacker who has been granted create or update access to applications to leak the contents of any text file on the repo-server by crafting a malicious Helm chart. Such text files could include sensitive information that the attacker should not have access to, compromising data confidentiality.

Description

A path traversal flaw was found in ArgoCD. This flaw allows an attacker who has been granted create or update access to applications to leak the contents of any text file on the repo-server by crafting a malicious Helm chart. Such text files could include sensitive information that the attacker should not have access to, compromising data confidentiality.

Additional Information

  • Bugzilla 2062755: CVE-2022-24731 argocd: path traversal allows leaking out-of-bound files
  • CWE-22->CWE-200: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') leads to Exposure of Sensitive Information to an Unauthorized Actor
  • FAQ: Frequently asked questions about CVE-2022-24731