GO-2024-2654
Dashboard / Vulnerabilities / GO-2024-2654
GO-2024-2654
Summary: Denial of service in github.com/argoproj/argo-cd/v2
Details: Application may crash due to concurrent writes, leading to a denial of service. An attacker can crash the application continuously, making it impossible for legitimate users to access the service. Authentication is not required in the attack.
References: https://github.com/argoproj/argo-cd/commit/2a22e19e06aaf6a1e734443043310a66c234e345, https://github.com/argoproj/argo-cd/commit/5bbb51ab423f273dda74ab956469843d2db2e208, https://github.com/argoproj/argo-cd/commit/ce04dc5c6f6e92033221ec6d96b74403b065ca8b, https://github.com/argoproj/argo-cd/blob/54601c8fd30b86a4c4b7eb449956264372c8bde0/util/session/sessionmanager.go#L302-L311
Affected packages
Package
Name: github.com/argoproj/argo-cd/v2
Purl: pkg:golang/github.com/argoproj/argo-cd/v2
Affected ranges
Type: SEMVER
Events:
