Source |
The Hacker News |
Identifiant |
4088212 |
Date de publication |
2022-02-05 21:48:25 (vue: 2022-02-06 07:06:11) |
Titre |
New Argo CD Bug Could Let Hackers Steal Secret Info from Kubernetes Apps |
Texte |
Users of the Argo continuous deployment (CD) tool for Kubernetes are being urged to push through updates after a zero-day vulnerability was found that could allow an attacker to extract sensitive information such as passwords and API keys.
The flaw, tagged as CVE-2022-24348 (CVSS score: 7.7), affects all versions and has been addressed in versions 2.3.0, 2.2.4, and 2.1.9. Cloud security firm |
Notes |
|
Envoyé |
Oui |
Condensat |
2022 24348 addressed affects after all allow api apps are argo as cve attacker been being bug cloud continuous could cvss day deployment extract firm flaw found from hackers has info information keys kubernetes let new passwords push score: secret security sensitive steal such tagged through tool updates urged users versions vulnerability zero |
Tags |
Tool
Vulnerability
|
Stories |
Uber
|
Move |
|