SCA: security update for github.com/argoproj/argo-cd/v2 (GHSA-47g2-qmh2-749v)

medium Tenable Cloud Security Plugin ID 420804

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered
in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes
Secret resource was synced from a repository. The vulnerability assumes the user has write access to the
repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to
repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the
exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13. (CVE-2025-23216)

See Also

https://github.com/advisories/GHSA-47g2-qmh2-749v

Plugin Details

Severity: Medium

ID: 420804

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/30/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.16

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N

CVSS Score Source: CVE-2025-23216

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/30/2025

Vulnerability Publication Date: 1/30/2025

Reference Information

CVE: CVE-2025-23216

cwe: CWE-200