<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:30:12.157183+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-03974</id>
    <title>bdu:2022-03974</title>
    <updated>2026-10-07T18:30:12.167403+00:00</updated>
    <content>bdu:2022-03974</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-03974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233966</id>
    <title>EUVD-2026-233966</title>
    <updated>2026-10-07T18:30:12.167443+00:00</updated>
    <content>EUVD-2026-233966</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31035</id>
    <title>fkie_cve-2022-31035</title>
    <updated>2026-10-07T18:30:12.167457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). The script would be capable of doing anything which is possible in the UI or via the API, such as creating, modifying, and deleting Kubernetes resources. A patch for this vulnerability has been released in the following Argo CD versions: v2.4.1, v2.3.5, v2.2.10 and v2.1.16. There are no completely-safe workarounds besides upgrading.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h4w9-6x78-8vrj</id>
    <title>GHSA-h4w9-6x78-8vrj — Argo CD's external URLs for Deployments can include JavaScript</title>
    <updated>2026-10-07T18:30:12.167490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd, Go: github.com/argoproj/argo-cd/v2</p>
<p>### Impact</p>
<p>All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin).</p>
<p>The script would be capable of doing anything which is possible in the UI or via the API, such as creating, modifying, and deleting Kubernetes resources.</p>
<p>### Patches</p>
<p>A patch for this vulnerability has been released in the following Argo CD versions:</p>
<p>* v2.4.1
* v2.3.5
* v2.2.10
* v2.1.16</p>
<p>### Workarounds</p>
<p>There are no completely-safe workarounds besides upgrading.</p>
<p>**Mitigations:**</p>
<p>1. Avoid clicking external links presented in the UI. Here is an example of an Application node with an external link:</p>
<p>![Application node in the Argo CD UI with an external link](https://user-images.githubusercontent.com/350466/171678146-026bbf20-2116-4b9f-8af8-7bb5b7ee8dff.png)</p>
<p>The link's title is user-configurable. So even if you hover the link, and the tooltip looks safe, the link might be malicious. The only way to be certain that the link is safe is to inspect the page's source.</p>
<p>2. Carefully limit who has permissions to edit resource manifests (this is configured in [RBAC](https://argo-cd.readthedocs.io/en/stable/operator-manual/rbac/)).</p>
<p>### References</p>
<p>* [Documentation for the external links feature](https://argo-cd.readthedocs.io/en/stable/user-guide/external-url/)</p>
<p>### Credits</p>
<p>Dis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h4w9-6x78-8vrj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31035</id>
    <title>gsd-2022-31035</title>
    <updated>2026-10-07T18:30:12.167545+00:00</updated>
    <content>gsd-2022-31035</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5152</id>
    <title>RHSA-2022:5152 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
    <updated>2026-10-07T18:30:12.167558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>argocd: vulnerable to an uncontrolled memory consumption bug argocd: vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or the UI. argocd: cross-site scripting (XSS) allow a malicious user to inject a javascript link in the UI argocd: vulnerable to a symlink following bug allowing a malicious user with repository write access</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5152"/>
  </entry>
</feed>
