In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 02 May 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. | |
| First Time appeared |
Argoproj
Argoproj argo Cd |
|
| Weaknesses | CWE-212 | |
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Argoproj
Argoproj argo Cd |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-02T01:42:18.517Z
Reserved: 2026-05-02T01:20:32.951Z
Link: CVE-2026-43824
No data.
Status : Received
Published: 2026-05-02T02:16:00.747
Modified: 2026-05-02T02:16:00.747
Link: CVE-2026-43824
No data.
OpenCVE Enrichment
No data.
Weaknesses