Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Loss
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the brute force login protection mechanism. Not only can they crash the service affecting all users, but they can also make unlimited login attempts, increasing the risk of account compromise. Versions 2.8.13, 2.9.9, and 2.10.4 contain a patch for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/argoproj/argo-cd/v2Go | < 2.8.13 | 2.8.13 |
github.com/argoproj/argo-cd/v2Go | >= 2.9.0, < 2.9.9 | 2.9.9 |
github.com/argoproj/argo-cd/v2Go | >= 2.10.0, < 2.10.4 | 2.10.4 |
Affected products
27- osv-coords26 versionspkg:apk/chainguard/argo-cd-2.10pkg:apk/chainguard/argo-cd-2.10-compatpkg:apk/chainguard/argo-cd-2.10-repo-serverpkg:apk/chainguard/argo-cd-2.8pkg:apk/chainguard/argo-cd-2.8-compatpkg:apk/chainguard/argo-cd-2.8-repo-serverpkg:apk/chainguard/argo-cd-2.9pkg:apk/chainguard/argo-cd-2.9-compatpkg:apk/chainguard/argo-cd-2.9-repo-serverpkg:apk/chainguard/argo-cd-fips-2.10pkg:apk/chainguard/argo-cd-fips-2.10-compatpkg:apk/chainguard/argo-cd-fips-2.10-repo-serverpkg:apk/chainguard/argo-cd-fips-2.9pkg:apk/chainguard/argo-cd-fips-2.9-compatpkg:apk/chainguard/argo-cd-fips-2.9-repo-serverpkg:apk/wolfi/argo-cd-2.10pkg:apk/wolfi/argo-cd-2.10-compatpkg:apk/wolfi/argo-cd-2.10-repo-serverpkg:apk/wolfi/argo-cd-2.8pkg:apk/wolfi/argo-cd-2.8-compatpkg:apk/wolfi/argo-cd-2.8-repo-serverpkg:apk/wolfi/argo-cd-2.9pkg:apk/wolfi/argo-cd-2.9-compatpkg:apk/wolfi/argo-cd-2.9-repo-serverpkg:bitnami/argo-cdpkg:golang/github.com/argoproj/argo-cd/v2
< 2.10.4-r0+ 25 more
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.10.4-r0
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.8.13-r1
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.9.9-r0
- (no CPE)range: < 2.10.4
- (no CPE)range: < 2.8.13
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-x32m-mvfj-52xvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-21652ghsaADVISORY
- argo-cd.readthedocs.io/en/stable/security_considerations/ghsaWEB
- github.com/argoproj/argo-cd/commit/17b0df1168a4c535f6f37e95f25ed7cd81e1fa4dghsaWEB
- github.com/argoproj/argo-cd/commit/6e181d72b31522f886a2afa029d5b26d7912ec7bghsaWEB
- github.com/argoproj/argo-cd/commit/cebb6538f7944c87ca2fecb5d17f8baacc431456ghsaWEB
- github.com/argoproj/argo-cd/security/advisories/GHSA-x32m-mvfj-52xvghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.