<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:29:19.740808+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14350</id>
    <title>bdu:2025-14350</title>
    <updated>2026-10-02T14:29:19.989268+00:00</updated>
    <content>bdu:2025-14350</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14350"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ac12204</id>
    <title>Withdrawn: CLEANSTART-2026-AC12204 — go-git is a highly extensible git implementation library written in pure Go</title>
    <updated>2026-10-02T14:29:19.989320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-cd-fips</p>
<p>Multiple security vulnerabilities affect the argo-cd-fips package. go-git is a highly extensible git implementation library written in pure Go. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ac12204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252074</id>
    <title>EUVD-2026-252074</title>
    <updated>2026-10-02T14:29:19.989364+00:00</updated>
    <content>EUVD-2026-252074</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55190</id>
    <title>fkie_cve-2025-55190</title>
    <updated>2026-10-02T14:29:19.989405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-786q-9hcg-v9ff</id>
    <title>GHSA-786q-9hcg-v9ff — Argo CD's Project API Token Exposes Repository Credentials</title>
    <updated>2026-10-02T14:29:19.989456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd/v3</p>
<p>### Summary
Argo CD API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets.</p>
<p>Component: `Project API (/api/v1/projects/{project}/detailed)`</p>
<p>## Vulnerability Details
### Expected Behavior
API tokens should require explicit permission to access sensitive credential information. Standard project permissions should not grant access to repository secrets.
### Actual Behavior
API tokens with basic project permissions can retrieve all repository credentials associated with a project through the detailed project API endpoint.</p>
<p>**Note**: This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`</p>
<p>### Steps to Reproduce</p>
<p>1. Create an API token with the following project-level permissions:
  ```
  p, proj:myProject:project-automation-role, applications, sync, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, action/argoproj.io/Rollout/*, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, get, myProject/*, allow
  ```</p>
<p>2. Call the project details API:
  ```
  bashcurl -sH "Authorization: Bearer $ARGOCD_API_TOKEN" \
    "https://argocd.example.com/api/v1/projects/myProject/detaile…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-786q-9hcg-v9ff"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1</id>
    <title>openSUSE-SU-2025:15538-1 — govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media</title>
    <updated>2026-10-02T14:29:19.989526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:15387</id>
    <title>RHSA-2025:15387 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
    <updated>2026-10-02T14:29:19.989561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:15387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1978</id>
    <title>WID-SEC-W-2025-1978 — Red Hat OpenShift GitOps (Argo CD): Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T14:29:19.989585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift GitOps (Argo CD) ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1978"/>
  </entry>
</feed>
