← Back

CVE-2021-23135

nvd nist
Published: May 12, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.

Affected (2)

Products: Argoproj: Argo Cd
1 product
Argo Cd
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Argoproj
From 1.7.0 to 1.7.14
From 1.8.0 to 1.8.7

References (2)

Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.