<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:38:49.382002+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00882</id>
    <title>bdu:2023-00882</title>
    <updated>2026-10-09T08:38:49.387127+00:00</updated>
    <content>bdu:2023-00882</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221555</id>
    <title>EUVD-2026-221555</title>
    <updated>2026-10-09T08:38:49.387160+00:00</updated>
    <content>EUVD-2026-221555</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-23947</id>
    <title>fkie_cve-2023-23947</title>
    <updated>2026-10-09T08:38:49.387174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23  2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one cluster secret to update any cluster secret. The attacker could use this access to escalate privileges (potentially controlling Kubernetes resources) or to break Argo CD functionality (by preventing connections to external clusters). A patch for this vulnerability has been released in Argo CD versions 2.6.2, 2.5.11, 2.4.23, and 2.3.17. Two workarounds are available. Either modify the RBAC configuration to completely revoke all `clusters, update` access, or use the `destinations` and `clusterResourceWhitelist` fields to apply similar restrictions as the `namespaces` and `clusterResources` fields.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-23947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jfq-742w-xg8j</id>
    <title>GHSA-3jfq-742w-xg8j — Users with any cluster secret update access may update out-of-bounds cluster secrets</title>
    <updated>2026-10-09T08:38:49.387206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd</p>
<p>### Impact</p>
<p>All Argo CD versions starting with v2.3.0-rc1 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one cluster secret to update any cluster secret.</p>
<p>The attacker could use this access to escalate privileges (potentially controlling Kubernetes resources) or to break Argo CD functionality (by preventing connections to external clusters).</p>
<p>#### How the Attack Works</p>
<p>Argo CD stores [cluster access configurations](https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#clusters) as Kubernetes Secrets. To take advantage of the vulnerability, an attacker must know the server URL for the cluster secret they want to modify.</p>
<p>The attacker must be authenticated with the Argo CD API server, and they must be authorized to update at least one ([non project-scoped](https://argo-cd.readthedocs.io/en/stable/user-guide/projects/#project-scoped-repositories-and-clusters)) cluster. Then they must craft a malicious request to the Argo CD API server.</p>
<p>#### Removing Deployment Restrictions</p>
<p>A cluster Secret's `clusterResources` field determines whether Argo CD users may deploy cluster-scoped resources to that cluster. The `namespaces` field determines the namespaces to which Argo CD users may deploy resources.</p>
<p>You can use this command to determine whether any of your cluster configurations employ these restrictions (replace `argocd` with the namespace of your Argo CD installation):</p>
<p>```shell
kubectl get secret…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jfq-742w-xg8j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-23947</id>
    <title>gsd-2023-23947</title>
    <updated>2026-10-09T08:38:49.387332+00:00</updated>
    <content>gsd-2023-23947</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-23947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0802</id>
    <title>RHSA-2023:0802 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
    <updated>2026-10-09T08:38:49.387346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0802"/>
  </entry>
</feed>
