CVE-2024-37152 is a high-severity vulnerability affecting Argo CD, a GitOps continuous delivery tool for Kubernetes. It allows unauthenticated attackers to access sensitive settings exposed via the /api/v1/settings endpoint, specifically the passwordPattern, due to missing authentication. This vulnerability has a CVSS score of 7.5 (HIGH) and an EPSS score indicating a high likelihood of exploitation, with a FAUCET Risk Score of 99/100, suggesting a critical risk. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this issue, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.9.3, < 2.9.17CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | ||
>= 2.10.0, < 2.10.12CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | ||
>= 2.11.0, < 2.11.3CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.