<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 15:49:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-234124</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234124</link>
      <description>EUVD-2026-234124</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234124</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24904</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24904</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD&amp;#39;s repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a directory-type Application may commit a symlink which points to an out-of-bounds file. Sensitive files which could be leaked include manifest files from other Applications&amp;#39; source repositories (potentially decrypted files, if you are using a decryption plugin) or any JSON-formatted secrets which have been mounted as files on the repo-server. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. Users of versions 2.3.0 or above who do not have any Jsonnet/directory-type Applications may disable the Jsonnet/directory config management tool as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD&amp;#39;s repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a directory-type Application may commit a symlink which points to an out-of-bounds file. Sensitive files which could be leaked include manifest files from other Applications&amp;#39; source repositories (potentially decrypted files, if you are using a decryption plugin) or any JSON-formatted secrets which have been mounted as files on the repo-server. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. Users of versions 2.3.0 or above who do not have any Jsonnet/directory-type Applications may disable the Jsonnet/directory config management tool as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24904</guid>
    </item>
    <item>
      <title>GHSA-6gcg-hp2x-q54h — Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6gcg-hp2x-q54h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;All unpatched versions of Argo CD starting with v0.7.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD&amp;#39;s repo-server.&lt;/p&gt;
&lt;p&gt;A malicious Argo CD user with write access for a repository which is (or may be) used in a directory-type Application may commit a symlink which points to an out-of-bounds file. 
* If the target file is a valid JSON or YAML manifest file, and the resource is allowed in the Application, the attacker can read the contents of that manifest file. (In versions &amp;lt;2.3.2, &amp;lt;2.2.8, and &amp;lt;2.1.14, the attacker may read the files contents even if the resource is _not_ allowed in the Application). 
* If the target file is valid JSON but is _not_ a manifest file, the attacker may read the contents of the file. 
* If the target file is not valid JSON or YAML, the attacker may read partial file contents (usually just the first character of the file).&lt;/p&gt;
&lt;p&gt;Sensitive files which could be leaked include manifest files from other Applications&amp;#39; source repositories (potentially decrypted files, if you are using a decryption plugin) or any JSON-formatted secrets which have been mounted as files on the repo-server.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;* v2.3.4
* v2.2.9
* v2.1.15&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;* If you are using &amp;gt;=v2.3.0 and do not have any Jsonnet/directory-type Applications, [disable the Jsonnet/directory config management too…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;All unpatched versions of Argo CD starting with v0.7.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD&amp;#39;s repo-server.&lt;/p&gt;
&lt;p&gt;A malicious Argo CD user with write access for a repository which is (or may be) used in a directory-type Application may commit a symlink which points to an out-of-bounds file. 
* If the target file is a valid JSON or YAML manifest file, and the resource is allowed in the Application, the attacker can read the contents of that manifest file. (In versions &amp;lt;2.3.2, &amp;lt;2.2.8, and &amp;lt;2.1.14, the attacker may read the files contents even if the resource is _not_ allowed in the Application). 
* If the target file is valid JSON but is _not_ a manifest file, the attacker may read the contents of the file. 
* If the target file is not valid JSON or YAML, the attacker may read partial file contents (usually just the first character of the file).&lt;/p&gt;
&lt;p&gt;Sensitive files which could be leaked include manifest files from other Applications&amp;#39; source repositories (potentially decrypted files, if you are using a decryption plugin) or any JSON-formatted secrets which have been mounted as files on the repo-server.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;* v2.3.4
* v2.2.9
* v2.1.15&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;* If you are using &amp;gt;=v2.3.0 and do not have any Jsonnet/directory-type Applications, [disable the Jsonnet/directory config management too…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6gcg-hp2x-q54h</guid>
    </item>
    <item>
      <title>gsd-2022-24904</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24904</link>
      <description>gsd-2022-24904</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24904</guid>
    </item>
    <item>
      <title>RHSA-2022:4671 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:4671</link>
      <description>&lt;p&gt;argocd: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server argocd: Login screen allows message spoofing if SSO is enabled argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;argocd: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server argocd: Login screen allows message spoofing if SSO is enabled argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:4671</guid>
    </item>
  </channel>
</rss>
