MEDIUM 6.5 Go

Argo Exposure of Sensitive Information

GHSA-xj7v-c82w-92q2 · CVE-2018-21034 · GO-2023-1952

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.

Ready to move

Start Securing

Free, no credit card | First findings in minutes