<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T22:43:19.613898+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05985</id>
    <title>bdu:2024-05985</title>
    <updated>2026-10-08T22:43:19.616715+00:00</updated>
    <content>bdu:2024-05985</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161076</id>
    <title>EUVD-2026-161076</title>
    <updated>2026-10-08T22:43:19.616752+00:00</updated>
    <content>EUVD-2026-161076</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36106</id>
    <title>fkie_cve-2024-36106</title>
    <updated>2026-10-08T22:43:19.616767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-36106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3cqf-953p-h5cp</id>
    <title>GHSA-3cqf-953p-h5cp — Argo-cd authenticated users can enumerate clusters by name</title>
    <updated>2026-10-08T22:43:19.616801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd</p>
<p>### Impact
It’s possible for authenticated users to enumerate clusters by name by inspecting error messages:</p>
<p>```
$ curl -k 'https://localhost:8080/api/v1/clusters/in-cluster?id.type=name' -H "Authorization: 
Bearer $token"
{"error":"permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z","code":7,"message":"permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z"}⏎                                 
                                   
$ curl -k 'https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name' -H "Authorizati
on: Bearer $token"
{"error":"permission denied","code":7,"message":"permission denied"}
```</p>
<p>It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters.
```
curl -k 'https://localhost:8080/api/v1/clusters/in-cluster-project?id.type=name' -H "Authorization: Bearer $token"
{"error":"permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z","code":7,"message":"permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z"}</p>
<p>curl -k 'https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name' -H "Authorization: Bearer $token"
{"error":"permission denied","code":7,"message":"permission denied"}
```</p>
<p>### Patches
A patch for this vulnerability has been released in the following Argo CD versions:</p>
<p>v2.11.3
v2.10.12
v2.9.17</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>Open…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3cqf-953p-h5cp"/>
  </entry>
</feed>
