CVE-2024-32476

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-05-14 15:36

Updated : 2025-01-09 16:59


NVD link : CVE-2024-32476

Mitre link : CVE-2024-32476

CVE.ORG link : CVE-2024-32476


JSON object : View

Products Affected

argoproj

  • argo_cd
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo