7.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Description
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
Basic Information
ID
CVE-2026-43824
Source
mitre
Published
May 2, 2026 at 01:20
Modified
May 2, 2026 at 01:42
Affected Product
Vendor
argoproj
Product
Argo CD
Version
3.2.0
Affected Versions
argoproj Argo CD 3.2.0
argoproj Argo CD 3.3.0
argoproj Argo CD 3.3.0