<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:28:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04887</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04887</link>
      <description>bdu:2022-04887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04887</guid>
    </item>
    <item>
      <title>EUVD-2026-233915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233915</link>
      <description>EUVD-2026-233915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233915</guid>
    </item>
    <item>
      <title>fkie_cve-2022-31105</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31105</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and 2.2.11. There are no complete workarounds, but a partial workaround is available. Those who use an external OIDC provider (not the bundled Dex instance), can mitigate the issue by setting the `oidc.config.rootCA` field in the `argocd-cm` ConfigMap. This mitigation only forces certificate validation when the API server handles login flows. It does not force certificate verification when verifying tokens on API calls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and 2.2.11. There are no complete workarounds, but a partial workaround is available. Those who use an external OIDC provider (not the bundled Dex instance), can mitigate the issue by setting the `oidc.config.rootCA` field in the `argocd-cm` ConfigMap. This mitigation only forces certificate validation when the API server handles login flows. It does not force certificate verification when verifying tokens on API calls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-31105</guid>
    </item>
    <item>
      <title>GHSA-7943-82jg-wmw5 — Argo CD certificate verification is skipped for connections to OIDC providers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7943-82jg-wmw5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;All versions of Argo CD starting with v0.4.0 are vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OIDC provider.&lt;/p&gt;
&lt;p&gt;(Note: external OIDC provider support was added in v0.11.0. Before that version, the notes below apply only to the bundled Dex instance.)&lt;/p&gt;
&lt;p&gt;You are impacted if 1) have SSO enabled and 2) insecure mode is _not_ enabled on the API server. In this case, certificate verification is skipped when connecting to your OIDC provider for the following tasks: verifying auth tokens on API requests and handling SSO login flows. If you are using the bundled Dex instance but have _not_ set the `--dex-server` flag on the API server to an HTTPS address, then certificate verification is not being skipped (because [TLS is not enabled by default for the bundled Dex instance](https://github.com/argoproj/argo-cd/issues/9424)).&lt;/p&gt;
&lt;p&gt;Argo CD sends requests to the configured OIDC provider (either the bundled Dex instance or an external provider) to 1) retrieve the [OpenID configuration](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig), 2) to retrieve the OIDC provider&amp;#39;s key set (at the location determined by the [OIDC provider&amp;#39;s configured `jwks_uri`](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)), and 3) (during an SSO login) to exchange an authorization code for a token.&lt;/p&gt;
&lt;p&gt;(Note: Starting with v2.3.0, certificate verification is _not_ skipped whe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;All versions of Argo CD starting with v0.4.0 are vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OIDC provider.&lt;/p&gt;
&lt;p&gt;(Note: external OIDC provider support was added in v0.11.0. Before that version, the notes below apply only to the bundled Dex instance.)&lt;/p&gt;
&lt;p&gt;You are impacted if 1) have SSO enabled and 2) insecure mode is _not_ enabled on the API server. In this case, certificate verification is skipped when connecting to your OIDC provider for the following tasks: verifying auth tokens on API requests and handling SSO login flows. If you are using the bundled Dex instance but have _not_ set the `--dex-server` flag on the API server to an HTTPS address, then certificate verification is not being skipped (because [TLS is not enabled by default for the bundled Dex instance](https://github.com/argoproj/argo-cd/issues/9424)).&lt;/p&gt;
&lt;p&gt;Argo CD sends requests to the configured OIDC provider (either the bundled Dex instance or an external provider) to 1) retrieve the [OpenID configuration](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig), 2) to retrieve the OIDC provider&amp;#39;s key set (at the location determined by the [OIDC provider&amp;#39;s configured `jwks_uri`](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)), and 3) (during an SSO login) to exchange an authorization code for a token.&lt;/p&gt;
&lt;p&gt;(Note: Starting with v2.3.0, certificate verification is _not_ skipped whe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7943-82jg-wmw5</guid>
    </item>
    <item>
      <title>gsd-2022-31105</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-31105</link>
      <description>gsd-2022-31105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-31105</guid>
    </item>
  </channel>
</rss>
