Related Vulnerabilities: CVE-2022-29165  

A flaw was found in the ArgoCD component of Red Hat GitOps, where an unauthenticated attacker can craft a malicious JWT token while ArgoCD's anonymous access is enabled and gains full access to the ArgoCD instance. This flaw allows the attacker to impersonate any ArgoCD user or role, fully compromising the targeted cluster's confidentiality, integrity, and availability.

Description

A flaw was found in the ArgoCD component of Red Hat GitOps, where an unauthenticated attacker can craft a malicious JWT token while ArgoCD's anonymous access is enabled and gains full access to the ArgoCD instance. This flaw allows the attacker to impersonate any ArgoCD user or role, fully compromising the targeted cluster's confidentiality, integrity, and availability.

Statement

The anonymous mode is by default disabled in the ArgoCD instance installed by the Red Hat GitOps operator.

The anonymous mode is by default disabled in the ArgoCD instance installed by the Red Hat GitOps operator.

Additional Information

  • Bugzilla 2081686: CVE-2022-29165 argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2022-29165