Upstream information
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
CNA (GitHub) | National Vulnerability Database | SUSE | |
---|---|---|---|
Base Score | 9 | 5.4 | 8.2 |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L |
Attack Vector | Network | Network | Network |
Attack Complexity | Low | Low | Low |
Privileges Required | Low | Low | Low |
User Interaction | Required | Required | Required |
Scope | Changed | Changed | Changed |
Confidentiality Impact | High | Low | Low |
Integrity Impact | High | Low | High |
Availability Impact | High | None | Low |
CVSSv3 Version | 3.1 | 3.1 | 3.1 |
SUSE Security Advisories:
- openSUSE-SU-2025:15188-1, published Mon Jun 2 18:51:31 2025
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2025-15188 |
SUSE Timeline for this CVE
CVE page created: Wed May 28 20:00:03 2025CVE page last modified: Thu Aug 28 01:24:54 2025