{"id":"GO-2022-0453","summary":"Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd","details":"Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server in github.com/argoproj/argo-cd","aliases":["CVE-2022-24904","GHSA-6gcg-hp2x-q54h"],"modified":"2026-03-03T04:50:23.862917Z","published":"2024-08-21T15:11:31Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2022-0453"},"references":[{"type":"ADVISORY","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-6gcg-hp2x-q54h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24904"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/5e767a4b9e30983330c0fdec322192281a90eb84"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/7357cfdb58a560de70a0538c6e3bef6fe39505ea"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/d36d95dc9f71ec61c1a93794f81ece6d61a0d943"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v2.1.15"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v2.2.9"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v2.3.4"}],"affected":[{"package":{"name":"github.com/argoproj/argo-cd","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0453.json"}},{"package":{"name":"github.com/argoproj/argo-cd/v2","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.15"},{"introduced":"2.2.0"},{"fixed":"2.2.9"},{"introduced":"2.3.0"},{"fixed":"2.3.4"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0453.json"}}],"schema_version":"1.7.3"}