In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

Project Subscriptions

Vendors Products
Argoproj Subscribe
Argo-cd Subscribe
Argo Cd Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 04 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 02 May 2026 10:30:00 +0000

Type Values Removed Values Added
Title Argo CD ServerSideDiff allows cleartext Kubernetes Secret exposure

Sat, 02 May 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Argoproj argo-cd
Vendors & Products Argoproj argo-cd

Sat, 02 May 2026 02:00:00 +0000

Type Values Removed Values Added
Description In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
First Time appeared Argoproj
Argoproj argo Cd
Weaknesses CWE-212
CPEs cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
Vendors & Products Argoproj
Argoproj argo Cd
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-04T13:32:17.895Z

Reserved: 2026-05-02T01:20:32.951Z

Link: CVE-2026-43824

cve-icon Vulnrichment

Updated: 2026-05-04T13:32:05.704Z

cve-icon NVD

Status : Deferred

Published: 2026-05-02T02:16:00.747

Modified: 2026-05-05T19:47:31.297

Link: CVE-2026-43824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T10:15:16Z

Weaknesses