Argo Rollouts Dashboard Unauthenticated Mutating Operations
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.3epss 0.4%
probabilidade de exploração
0.4%top 63% das CVEs
exploração observada
nãonenhuma fonte reporta
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
argoproj · argo-rolloutsReferências
https://github.com/argoproj/argo-rolloutshttps://github.com/argoproj/argo-rollouts/blob/4e6a2798688e22868340d9871a3c8d78371f1568/server/server.gohttps://github.com/argoproj/argo-rollouts/issues/4747https://www.vulncheck.com/advisories/argo-rollouts-dashboard-unauthenticated-mutating-operations