VDB

CVE-2021-3557

CVE-2021-3557 PUBLISHED CVSS 4 MEDIUM

A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.

EPSS 0.76% · 52.0th percentile

Risk Scores

CVSS 2.0
4
EPSS Score
0.76%
52.0th percentile

Affected Products

VendorProductVersions
redhatopenshift_gitops1.1
argoprojargo_cd0
n/aargocd*

Timeline

  • Feb 16, 2022 CVE Published
  • Feb 17, 2022 EPSS Score
  • Apr 10, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Jul 25, 2022 EPSS Score
  • Sep 15, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Dec 28, 2022 EPSS Score
  • Feb 18, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 11, 2023 EPSS Score
  • Jun 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›