GO-2022-0453
Dashboard / Vulnerabilities / GO-2022-0453
GO-2022-0453
Summary: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd
Details: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd
References: https://github.com/argoproj/argo-cd/security/advisories/GHSA-6gcg-hp2x-q54h, https://nvd.nist.gov/vuln/detail/CVE-2022-24904, https://github.com/argoproj/argo-cd/commit/5e767a4b9e30983330c0fdec322192281a90eb84, https://github.com/argoproj/argo-cd/commit/7357cfdb58a560de70a0538c6e3bef6fe39505ea, https://github.com/argoproj/argo-cd/commit/d36d95dc9f71ec61c1a93794f81ece6d61a0d943, https://github.com/argoproj/argo-cd/releases/tag/v2.1.15, https://github.com/argoproj/argo-cd/releases/tag/v2.2.9, https://github.com/argoproj/argo-cd/releases/tag/v2.3.4
Affected packages
Package
Name: github.com/argoproj/argo-cd
Purl: pkg:golang/github.com/argoproj/argo-cd
Affected ranges
Type: SEMVER
Events:
