Argo Rollouts Dashboard Unauthenticated Mutating Operations
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.4%
probabilidad de explotación
0.4%top 63% de las CVE
explotación observada
noninguna fuente lo reporta
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
argoproj · argo-rolloutsReferencias
https://github.com/argoproj/argo-rolloutshttps://github.com/argoproj/argo-rollouts/blob/4e6a2798688e22868340d9871a3c8d78371f1568/server/server.gohttps://github.com/argoproj/argo-rollouts/issues/4747https://www.vulncheck.com/advisories/argo-rollouts-dashboard-unauthenticated-mutating-operations