CVE-2023-40584
Last modified
CVE-2023-40584 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a user-controlled tar.gz file without validating the size of its inner files. As a result, a malicious, low-privileged user can send a malicious tar.gz file that exploits this vulnerability to the repo-server, thereby harming the system's functionality and availability. Additionally, the repo-server is susceptible to another vulnerability due to the fact that it does not check the extracted file permissions before attempting to delete them. Consequently, an attacker can craft a malicious tar.gz archive in a way that prevents the deletion of its inner files when the manifest generation process is completed. A patch for this vulnerability has been released in versions 2.6.15, 2.7.14, and 2.8.3. Users are advised to upgrade. The only way to completely resolve the issue is to upgrade, however users unable to upgrade should configure RBAC (Role-Based Access Control) and provide access for configuring applications only to a limited number of administrators. These administrators should utilize trusted and verified Helm charts.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Argoproj | Argo Cd | >= 2.4.0, < 2.6.15 |
| Argoproj | Argo Cd | >= 2.7.0, < 2.7.14 |
| Argoproj | Argo Cd | >= 2.8.0, < 2.8.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40584?
How severe is CVE-2023-40584?
How do I fix CVE-2023-40584?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-40579OpenFGA is an authorization/permission engine built for deve…6.5
- CVE-2023-4058Memory safety bugs present in Firefox 115. Some of these bug…9.8
- CVE-2023-40580Freighter is a Stellar chrome extension. It may be possible …6.5
- CVE-2023-40581yt-dlp is a youtube-dl fork with additional features and fix…7.8
- CVE-2023-40582find-exec is a utility to discover available shell commands.…9.8
- CVE-2023-40583libp2p is a networking stack and library modularized out of …7.5
- CVE-2023-40585ironic-image is a container image to run OpenStack Ironic as…7.5
- CVE-2023-40586OWASP Coraza WAF is a golang modsecurity compatible web appl…7.5
- CVE-2023-40587Pyramid is an open source Python web framework. A path trave…5.3
- CVE-2023-40588Discourse is an open-source discussion platform. Prior to ve…6.5
- CVE-2023-40589FreeRDP is a free implementation of the Remote Desktop Proto…7.5
- CVE-2023-4059The Profile Builder WordPress plugin before 3.9.8 lacks auth…4.3
Are you affected by CVE-2023-40584?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
