Executive brief
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd
Affected products
- Go github.com/argoproj/argo-cd
- Go github.com/argoproj/argo-cd/v2
Junglewise Threat Intelligence
CVE-2022-31036 · Severity: low · CVSS 3.1 · Published 2024-08-21
Technologies: github.com/argoproj/argo-cd (Go), github.com/argoproj/argo-cd/v2 (Go). Vendors: Go.
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd