VDB
CVE-2022-1025
CVE-2022-1025
PUBLISHED
CVSS 8.800000190734863 HIGH
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level
EPSS 1.25% · 66.4th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.25%
66.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | argoproj/argo-cd | 0.5.0 |
| n/a | ArgoCD | 0.5.0 through 2.1.12, 2.2.7, 2.3.1 |
| github.com | argoproj/argo-cd/v2 | 2.2.0, 2.3.0, 0 |
| argoproj | argo_cd | 0.5.0, 2.2.0, 2.3.0 |
Timeline
- Jul 12, 2022 CVE Published
- Jul 13, 2022 EPSS Score
- Aug 30, 2022 EPSS Score
- Oct 16, 2022 EPSS Score
- Dec 2, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jun 27, 2023 CVE Updated
- Jul 26, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
References
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-2f5v-8r3f-8pww url
- https://nvd.nist.gov/vuln/detail/CVE-2022-1025 advisory
- https://github.com/argoproj/argo-cd/commit/af03b291d4b7e9d3ce9a6580ae9c8141af0e05cf url
- https://access.redhat.com/errata/RHSA-2022:1039 url
- https://access.redhat.com/errata/RHSA-2022:1040 url
- https://access.redhat.com/errata/RHSA-2022:1041 url
- https://access.redhat.com/errata/RHSA-2022:1042 url
- https://access.redhat.com/security/cve/CVE-2022-1025 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2064682 url
- https://github.com/argoproj/argo-cd package