logo

Warning: Exposure Of Sensitive Information in Argo CD, Patch Immediately!

ID: 0b000a66-d92a-5c93-9ba3-98e82f425e3c

STIX ID: report--0b000a66-d92a-5c93-9ba3-98e82f425e3c

Feed Name: CCB Advisories Feed

Threat Score
85/100

Date Published: 2025-09-09

Date Updated: 2026-07-24

...
...

A critical Argo CD vulnerability (CVE-2025-55190, CVSS 9.9) affecting multiple 2.13.x, 2.14.x, 3.0.x and 3.1.x releases allows API tokens with project-level or project-get permissions to exfiltrate repository credentials (usernames/passwords) via the project details API endpoint; fixes are available in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2 and organizations are urged to patch immediately and increase monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.