{"id":"BIT-argo-cd-2021-23347","details":"The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.","aliases":["CVE-2021-23347","GHSA-qq5v-f4c3-395c","GO-2022-0869","SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291"],"modified":"2026-07-08T06:49:37.661885616Z","published":"2024-03-06T10:51:28.083Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:linuxfoundation:argo_continuous_delivery:*:*:*:*:*:kubernetes:*:*"]},"references":[{"type":"WEB","url":"https://github.com/argoproj/argo-cd/pull/5563"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291"}],"affected":[{"package":{"name":"argo-cd","ecosystem":"Bitnami","purl":"pkg:bitnami/argo-cd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.13"},{"introduced":"1.8.0"},{"fixed":"1.8.6"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/argo-cd/BIT-argo-cd-2021-23347.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}],"schema_version":"1.7.5"}