CVE-2024-32476
published 2024-05-14CVE-2024-32476: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.00%
58.6th percentile
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argoproj | argo-cd | < 2.8.17 | 2.8.17 |
| argoproj | argo-cd | — | — |
| argoproj | argo-cd | — | — |
| argoproj | argo_cd | >= 2.1.0 < 2.8.17 | 2.8.17 |
| argoproj | argo_cd | >= 2.10.0 < 2.10.8 | 2.10.8 |
| argoproj | argo_cd | >= 2.9.0 < 2.9.13 | 2.9.13 |
| github.com | argoproj_argo-cd_v2 | >= 0 < 2.8.17 | 2.8.17 |
| github.com | argoproj_argo-cd_v2 | >= 2.10.0 < 2.10.8 | 2.10.8 |
| github.com | argoproj_argo-cd_v2 | >= 2.9.0 < 2.9.13 | 2.9.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd
osv·2024-06-04
CVE-2024-32476 Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd
OSV
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
osv·2024-04-26
CVE-2024-32476 [MEDIUM] Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
### Impact
DoS vuln via OOM using jq in ignoreDifferences.
```
ignoreDifferences:
- group: apps
kind: Deployment
jqPathExpressions:
- 'until(true == false; [.] + [1])'
```
### Patches
A patch for this vulnerability has been released in the following Argo CD versions:
v2.10.8
v2.9.13
v2.8.17
### For more information
If you have any questions or comments about this advisory:
Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd
Credits
This vulnerability was found & reported by @crenshaw-dev (Michael Crens
GHSA
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
ghsa·2024-04-26
CVE-2024-32476 [MEDIUM] CWE-400 Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
### Impact
DoS vuln via OOM using jq in ignoreDifferences.
```
ignoreDifferences:
- group: apps
kind: Deployment
jqPathExpressions:
- 'until(true == false; [.] + [1])'
```
### Patches
A patch for this vulnerability has been released in the following Argo CD versions:
v2.10.8
v2.9.13
v2.8.17
### For more information
If you have any questions or comments about this advisory:
Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd
Credits
This vulnerability was found & reported by @crenshaw-dev (Michael Crens
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5ahttps://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cachttps://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frqhttps://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5ahttps://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cachttps://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq
2024-05-14
Published