{"id":6728,"date":"2025-09-07T10:03:48","date_gmt":"2025-09-07T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/07\/critical-argo-cd-api-vulnerability-exposes-repository-credentials\/"},"modified":"2025-09-07T10:03:48","modified_gmt":"2025-09-07T10:03:48","slug":"critical-argo-cd-api-vulnerability-exposes-repository-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/07\/critical-argo-cd-api-vulnerability-exposes-repository-credentials\/","title":{"rendered":"Critical Argo CD API Vulnerability Exposes Repository Credentials"},"content":{"rendered":"<p>    Critical Argo CD API Vulnerability Exposes Repository Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability has been discovered in Argo CD that allows API tokens with limited permissions to access sensitive repository credentials.<\/p>\n<p>The flaw in the project details API endpoint exposes usernames and passwords, undermining the platform\u2019s security model by granting access to secrets without explicit permissions.<\/p>\n<p>The vulnerability stems from an improper authorization check in the Project API, specifically the <code>\/api\/v1\/projects\/{project}\/detailed<\/code> endpoint.<\/p>\n<p>According to the vulnerability details, <a href=\"https:\/\/cybersecuritynews.com\/internet-archive-breached-again\/\" target=\"_blank\" rel=\"noreferrer noopener\">API tokens<\/a> with standard project-level permissions, such as those for managing applications, can retrieve all repository credentials associated with that project.<\/p>\n<p>The expected behavior is that any request for sensitive information, like secrets, would require explicit, elevated permissions. However, the actual behavior allows tokens with basic access to fetch this data.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-exploitation\"><strong>Exploitation<\/strong><\/h2>\n<p>This issue is not confined to project-specific roles. Any token holding <code>project get<\/code> permissions is considered vulnerable, including those with broader global permissions like <code>p, role\/user, projects, get, *, allow<\/code>. This widens the potential attack surface significantly, as more general-purpose tokens could be used to exploit the flaw.<\/p>\n<p>Exploitation is straightforward. An attacker in possession of a valid API token with the necessary permissions can make a simple authenticated call to the detailed project <a href=\"https:\/\/cybersecuritynews.com\/api-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">API endpoint<\/a>.<\/p>\n<p>The resulting JSON response will incorrectly include an <code>repositories<\/code> object containing plaintext <code>username<\/code> and <code>password<\/code> credentials for the repositories connected to the project. This allows an attacker to easily harvest credentials that can be used to access private source code repositories.<\/p>\n<p>The consequences of this vulnerability are severe, as exposed credentials could lead to source code theft, malicious code injection into the CI\/CD pipeline, and further compromise of development infrastructure.<\/p>\n<p>The Argo CD development team <a href=\"https:\/\/github.com\/argoproj\/argo-cd\/security\/advisories\/GHSA-786q-9hcg-v9ff\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">has addressed<\/a> the issue and released patches. Administrators are strongly advised to upgrade their instances to one of the following secure versions immediately to mitigate the risk:<\/p>\n<ul class=\"wp-block-list\">\n<li>v3.1.2<\/li>\n<li>v3.0.14<\/li>\n<li>v2.14.16<\/li>\n<li>v2.13.9<\/li>\n<\/ul>\n<p>Upgrading to a patched version will ensure that the API endpoint properly enforces permission checks and prevents the unauthorized disclosure of repository credentials.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/argo-cd-api-vulnerability\/\">Critical Argo CD API Vulnerability Exposes Repository Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/argo-cd-api-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Argo CD API Vulnerability Exposes Repository Credentials A critical vulnerability has been discovered in Argo CD that allows API tokens with limited permissions to access sensitive repository credentials. The flaw in the project details API endpoint exposes usernames and passwords, undermining the platform\u2019s security model by granting access to secrets without explicit permissions. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-6728","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6728"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6728"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6728\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}