SCA: security update for github.com/argoproj/argo-cd (GHSA-pmjg-52h9-72qv)

medium Tenable Cloud Security Plugin ID 417604

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and
prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker
to inject arbitrary JavaScript in the `/auth/callback` page in a victim's browser. This vulnerability only
affects Argo CD instances which have single sign on (SSO) enabled. The exploit also assumes the attacker
has 1) access to the API server's encryption key, 2) a method to add a cookie to the victim's browser, and
3) the ability to convince the victim to visit a malicious `/auth/callback` link. The vulnerability is
classified as low severity because access to the API server's encryption key already grants a high level
of access. Exploiting the XSS would allow the attacker to impersonate the victim, but would not grant any
privileges which the attacker could not otherwise gain using the encryption key. A patch for this
vulnerability has been released in the following Argo CD versions 2.4.5 and 2.3.6. There is currently no
known workaround. (CVE-2022-31102)

See Also

https://github.com/advisories/GHSA-pmjg-52h9-72qv

Plugin Details

Severity: Medium

ID: 417604

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2022-31102

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/12/2022

Vulnerability Publication Date: 7/12/2022

Reference Information

CVE: CVE-2022-31102

cwe: CWE-79