Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

Apiiro Discovers 0-Day Software Supply Chain Vulnerability in Argo CD

Malicious Kubernetes Helm Charts can be used to steal passwords, secrets, and API keys.


News provided by

Apiiro

04 Feb, 2022, 18:39 IST

Share this article

Share toX

Share this article

Share toX

TEL AVIV and NEW YORK, Feb. 4, 2022 /PRNewswire/ -- Apiiro, the leader in Cloud-Native Application Security, today announced a major software supply chain zero-day vulnerability in Argo CD, the popular open source Continuous Delivery platform. The vulnerability enables attackers to access sensitive information such as secrets, passwords, and API keys, which can be used to escalate privileges and gain access to additional systems and resources.

The vulnerability (CVE-2022-24348), with a CVSS score of 7.7, allows malicious actors to load a Kubernetes Helm Chart YAML file to the vulnerability and "hop" from their application ecosystem to other applications' data outside of the user's scope. The actors can then read and exfiltrate data residing in other applications.

The impact of the vulnerability is two-fold:

  • First, contents read from other files present on the reposerver may contain sensitive information.
  • Second, an attacker can use secrets, tokens, and keys often found in application files to escalate privileges or gain a foothold on additional systems.

"Supply chain attacks will continue to accelerate and it's essential that Security researchers focus on securing the modern, cloud-native SDLC," commented Moshe Zioni, Apiiro's VP of Security Research.

Apiiro worked closely with the Argo CD team, which resolved the vulnerability and alerted their users to upgrade immediately to the newly-released versions 2.1.9 and 2.2.4.

Additional technical details can be found here.

About Apiiro

Apiiro helps security and development teams proactively remediate risk before releasing to the cloud. Apiiro is re-inventing risk remediation for Cloud-Native applications. Backed by Greylock and Kleiner Perkins. www.apiiro.com

Contact:

Kelly Hall
Offleash PR for Apiiro 
[email protected]

SOURCE Apiiro

Modal title

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2025 Cision US Inc.