One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 5679746
Date de publication 2022-07-12 22:15:08 (vue: 2022-07-13 01:06:36)
Titre CVE-2022-31105
Texte Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and 2.2.11. There are no complete workarounds, but a partial workaround is available. Those who use an external OIDC provider (not the bundled Dex instance), can mitigate the issue by setting the `oidc.config.rootCA` field in the `argocd-cm` ConfigMap. This mitigation only forces certificate validation when the API server handles login flows. It does not force certificate verification when verifying tokens on API calls.
Envoyé Oui
Condensat 2022 31105 `argocd `oidc api are argo available been bug bundled but calls can cause certificate cm` complete config configmap connect continuous could cve declarative delivery dex does external field flows force forces gitops handles has improper instance issue kubernetes login malicious mitigate mitigation not oidc only openid otherwise partial patch prior provider released rootca` server setting starting those tokens tool trust untrustworthy use validation verification verifying version versions vulnerability vulnerable when which who workaround workarounds
Tags Tool Vulnerability
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: