Miggo Logo

CVE-2022-29165: Argo CD will blindly trust JWT claims if anonymous access is enabled

10

CVSS Score
3.1

Basic Information

EPSS Score
0.47983%
Published
5/24/2022
Updated
1/27/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/argoproj/argo-cd/v2go>= 2.3.0, < 2.3.42.3.4
github.com/argoproj/argo-cd/v2go>= 2.2.0, < 2.2.92.2.9
github.com/argoproj/argo-cd/v2go< 2.1.152.1.15
github.com/argoproj/argo-cdgo<= 1.8.72.1.15

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t * *riti**l vuln*r**ility **s ***n *is*ov*r** in *r*o ** w*i** woul* *llow un*ut**nti**t** us*rs to imp*rson*t* *s *ny *r*o ** us*r or rol*, in*lu*in* t** `**min` us*r, *y s*n*in* * sp**i*i**lly *r**t** JSON W** Tok*n (JWT) *lon* wit* t**

Reasoning

No *n*lysis *v*il**l*