VDB
CVE-2021-3557
CVE-2021-3557
PUBLISHED
CVSS 4 MEDIUM
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
EPSS 0.76% · 52.0th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
0.76%
52.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | openshift_gitops | 1.1 |
| argoproj | argo_cd | 0 |
| n/a | argocd | * |
Timeline
- Feb 16, 2022 CVE Published
- Feb 17, 2022 EPSS Score
- Apr 10, 2022 EPSS Score
- Jun 1, 2022 EPSS Score
- Jul 25, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Feb 18, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 11, 2023 EPSS Score
- Jun 3, 2023 EPSS Score