Synacktiv said it found a flaw in Argo CD, a tool that deploys apps to Kubernetes. It sits in the repo-server, which fetches files from Git repositories. Synacktiv said the server's gRPC interface, a way for programs to call each other, checks no credentials. The API server normally sends it Kustomize settings, and it takes them from any caller. An attacker who can reach it can name a program to run on files from a Git repository the attacker picks. Synacktiv said this could give full control of the cluster.
Synacktiv's public write-up gives no CVE number, affected versions or patch status. It does not say whether attackers have used the flaw. Synacktiv said an attacker must first reach the repo-server, but how that happens is not covered here. It also describes a route to the cluster through Redis, a cache database. The steps are not given.
The flaw turns on a service that does not check who calls it. Argo CD holds wide rights in the cluster and can reach private Git repositories. Teams can ask who and what can reach the repo-server and Redis. Argo CD's documentation, quoted by Synacktiv, says secrets that plugins add are available to anyone with access to either.