Bug 2270173 (CVE-2024-21661) - CVE-2024-21661 argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment
Summary: CVE-2024-21661 argo-cd: Denial of Service Due to Unsafe Array Modification in...
Keywords:
Status: NEW
Alias: CVE-2024-21661
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2270175
Blocks: 2270183
TreeView+ depends on / blocked
 
Reported: 2024-03-18 19:38 UTC by Pedro Sampaio
Modified: 2024-04-10 12:42 UTC (History)
6 users (show)

Fixed In Version: argo-cd 2.10.4, argo-cd 2.9.9, argo-cd 2.8.13
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Argo CD that may result in a remote denial of service. The expireOldFailedAttempts function modifies an array while it is being iterated over. This issue may cause an application crash when executed in a multi-threaded environment if two threads interact with the same array simultaneously.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:1697 0 None None None 2024-04-08 13:36:21 UTC
Red Hat Product Errata RHSA-2024:1700 0 None None None 2024-04-08 16:37:18 UTC
Red Hat Product Errata RHSA-2024:1752 0 None None None 2024-04-10 12:17:57 UTC
Red Hat Product Errata RHSA-2024:1753 0 None None None 2024-04-10 12:42:06 UTC

Description Pedro Sampaio 2024-03-18 19:38:44 UTC
An attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment.

References:

https://github.com/argoproj/argo-cd/security/advisories/GHSA-6v85-wr92-q4p7

Comment 3 errata-xmlrpc 2024-04-08 13:36:20 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift GitOps 1.11

Via RHSA-2024:1697 https://access.redhat.com/errata/RHSA-2024:1697

Comment 4 errata-xmlrpc 2024-04-08 16:37:17 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift GitOps 1.10

Via RHSA-2024:1700 https://access.redhat.com/errata/RHSA-2024:1700

Comment 5 errata-xmlrpc 2024-04-10 12:17:56 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift GitOps 1.12
  Red Hat OpenShift GitOps 1.12 - RHEL 9

Via RHSA-2024:1752 https://access.redhat.com/errata/RHSA-2024:1752

Comment 6 errata-xmlrpc 2024-04-10 12:42:04 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift GitOps 1.12
  Red Hat OpenShift GitOps 1.12 - RHEL 9

Via RHSA-2024:1753 https://access.redhat.com/errata/RHSA-2024:1753


Note You need to log in before you can comment on or make changes to this bug.