Fedora Account System
Red Hat Associate
Red Hat Customer
Impacts for versions starting with v1.0.0 All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.3 Via RHSA-2022:1040 https://access.redhat.com/errata/RHSA-2022:1040
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.4 Via RHSA-2022:1041 https://access.redhat.com/errata/RHSA-2022:1041
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.2 Via RHSA-2022:1039 https://access.redhat.com/errata/RHSA-2022:1039
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.3 Via RHSA-2022:1042 https://access.redhat.com/errata/RHSA-2022:1042
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1025