Argo CD vulnerable to Denial of Service (DoS) attack due to unsafe array manipulation in multi-threaded environment
CVE-2024-21661
7.5HIGH
Key Information:
What is CVE-2024-21661?
A Denial of Service vulnerability has been identified in Argo CD, a popular GitOps continuous delivery tool for Kubernetes. This vulnerability arises from unsafe array manipulation within a multi-threaded environment, which could allow attackers to crash the application by simultaneously interacting with the same array. The flaw does not require authentication, making it particularly dangerous as it opens the possibility for any adversary to disrupt service availability. Versions 2.8.13, 2.9.9, and 2.10.4 have been patched to mitigate this vulnerability, emphasizing the importance of timely updates for users.
Affected Version(s)
argo-cd < 2.8.13 < 2.8.13
argo-cd >= 2.9.0, < 2.9.9 < 2.9.0, 2.9.9
argo-cd >= 2.10.0, < 2.10.4 < 2.10.0, 2.10.4