Argo CD vulnerable to Denial of Service (DoS) attack due to unsafe array manipulation in multi-threaded environment
CVE-2024-21661
What is CVE-2024-21661?
A Denial of Service vulnerability has been identified in Argo CD, a popular GitOps continuous delivery tool for Kubernetes. This vulnerability arises from unsafe array manipulation within a multi-threaded environment, which could allow attackers to crash the application by simultaneously interacting with the same array. The flaw does not require authentication, making it particularly dangerous as it opens the possibility for any adversary to disrupt service availability. Versions 2.8.13, 2.9.9, and 2.10.4 have been patched to mitigate this vulnerability, emphasizing the importance of timely updates for users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
argo-cd < 2.8.13 < 2.8.13
argo-cd >= 2.9.0, < 2.9.9 < 2.9.0, 2.9.9
argo-cd >= 2.10.0, < 2.10.4 < 2.10.0, 2.10.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
