CVE-2025-55190: ArgoCD Project API Token Repository Credentials Exposure

CVE-2025-55190: ArgoCD Project API Token Repository Credentials Exposure-渗透云记 - 专注于网络安全与技术分享
CVE-2025-55190: ArgoCD Project API Token Repository Credentials Exposure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-55190: ArGoCD Project API Token Repository Credentials Exposure

漏洞描述

Argo CD API tokens with project-level permissions are able to retrieve sensitive repository credentials

(usernames, passwords) through the project details API endpoint, even when the token only has standard

application management permissions and no explicit access to secrets. This vulnerability affects versions

v2.2.0-rc1 and later, including 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12,

and 3.1.0-rc1 through 3.1.1. Any token with project get permissions is vulnerable, including global permissions.

Note: This template requires valid ArgoCD credentials (username/password) to test the vulnerability.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享