Executive brief
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd
Affected products
- Go github.com/argoproj/argo-cd
- Go github.com/argoproj/argo-cd/v2
Junglewise Threat Intelligence
CVE-2022-29165 · Severity: low · CVSS 3.1 · Published 2024-08-21
Technologies: github.com/argoproj/argo-cd (Go), github.com/argoproj/argo-cd/v2 (Go). Vendors: Go.
Argo CD will blindly trust JWT claims if anonymous access is enabled in github.com/argoproj/argo-cd