Fedora Account System
Red Hat Associate
Red Hat Customer
An unauthenticated attacker can exploit the Argo CD repo-server's GenerateManifest gRPC endpoint by supplying malicious KustomizeOptions (specifically BuildOptions or BinaryPath), causing arbitrary commands to be executed in the repo-server pod. When combined with Redis cache manipulation, this can result in the deployment of attacker-controlled Kubernetes manifests, potentially leading to complete compromise of the Kubernetes cluster.