BIT-argo-cd-2024-21652

    Dashboard / Vulnerabilities / BIT-argo-cd-2024-21652

    BIT-argo-cd-2024-21652

    Published: 31 Mar 2024Last Modified: 8 Sept 2026

    Summary: Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Loss

    Details: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the brute force login protection mechanism. Not only can they crash the service affecting all users, but they can also make unlimited login attempts, increasing the risk of account compromise. Versions 2.8.13, 2.9.9, and 2.10.4 contain a patch for this issue.

    Affected packages

    Package

    Name: argo-cd

    Purl: pkg:bitnami/argo-cd

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.10.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-argo-cd-2024-21652 | CVE-DB