VDB

CVE-2022-31035

CVE-2022-31035 PUBLISHED CVSS 9 CRITICAL

Argo CD's external URLs for Deployments can include JavaScript

EPSS 0.92% · 56.8th percentile

Risk Scores

CVSS 3.1
9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.92%
56.8th percentile

Affected Products

VendorProductVersions
argoprojargo_cd2.4.0, 1.0.0, 2.2.9
argoprojargo-cd>= 2.4.0, < 2.4.1, *, >= 2.2.0, < 2.2.10
github.comargoproj/argo-cd/v22.4.0, 0, 2.3.0
github.comargoproj/argo-cd1.0.0

Timeline

  • Jun 21, 2022 CVE Published
  • Jun 28, 2022 EPSS Score
  • Aug 16, 2022 EPSS Score
  • Oct 2, 2022 EPSS Score
  • Nov 19, 2022 EPSS Score
  • Jan 6, 2023 EPSS Score
  • Feb 22, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 11, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 15, 2023 EPSS Score
  • Sep 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›