CVE-2022-24768

    Dashboard / Vulnerabilities / CVE-2022-24768

    CVE-2022-24768

    Published: 23 Mar 2022Last Modified: 12 Aug 2026

    Summary: Improper access control allows admin privilege escalation in Argo CD

    Details: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting with 0.8.0 and 0.5.0 contain limited versions of this issue. To perform exploits, an authorized Argo CD user must have push access to an Application's source git or Helm repository or `sync` and `override` access to an Application. Once a user has that access, different exploitation levels are possible depending on their other RBAC privileges. A patch for this vulnerability has been released in Argo CD versions 2.3.2, 2.2.8, and 2.1.14. Some mitigation measures are available but do not serve as a substitute for upgrading. To avoid privilege escalation, limit who has push access to Application source repositories or `sync` + `override` access to Applications; and limit which repositories are available in projects where users have `update` access to Applications. To avoid unauthorized resource inspection/tampering, limit who has `delete`, `get`, or `action` access to Applications.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- df0e2e4015c4cff4e16c8743df9d62f5ca1bdc24

    Affected versions

    v2.1.13
    v2.1.12
    v2.1.11
    v2.1.10
    v2.1.9
    v2.1.8
    v2.1.7
    v2.1.2
    v2.1.6
    v2.1.5
    v2.1.4
    v2.1.3
    v2.1.1
    v2.1.0
    v2.1.0-rc3
    v2.1.0-rc2
    v2.1.0-rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-24768 | CVE-DB