Denial of Service Vulnerability in Argo CD for Kubernetes
CVE-2024-32476
6.5MEDIUM
Key Information:
What is CVE-2024-32476?
Argo CD, a declarative GitOps continuous delivery tool designed for Kubernetes, is susceptible to a Denial of Service (DoS) vulnerability. This issue arises from an out-of-memory (OOM) condition when utilizing 'jq' in the ignoreDifferences feature. Attackers exploiting this vulnerability can lead to service disruptions. The vulnerability has been addressed in subsequent releases: 2.10.7, 2.9.12, and 2.8.16. Users are encouraged to upgrade to these versions to safeguard their deployments.