Skip to content
Brief Security & Trust ·

Synacktiv finds unauthenticated code execution flaw in Argo CD

The security firm says a part of the deployment tool accepts commands from anyone who can reach it.

In brief
  • Synacktiv says an attacker who can reach Argo CD's repo-server can run code there, because its gRPC interface has no login check. How an attacker gets that access is not covered here.
  • No CVE number, affected versions or patch status are given. It is not said whether attacks have happened.

Synacktiv said it found a flaw in Argo CD, a tool that deploys apps to Kubernetes. It sits in the repo-server, which fetches files from Git repositories. Synacktiv said the server's gRPC interface, a way for programs to call each other, checks no credentials. The API server normally sends it Kustomize settings, and it takes them from any caller. An attacker who can reach it can name a program to run on files from a Git repository the attacker picks. Synacktiv said this could give full control of the cluster.

Synacktiv's public write-up gives no CVE number, affected versions or patch status. It does not say whether attackers have used the flaw. Synacktiv said an attacker must first reach the repo-server, but how that happens is not covered here. It also describes a route to the cluster through Redis, a cache database. The steps are not given.

The flaw turns on a service that does not check who calls it. Argo CD holds wide rights in the cluster and can reach private Git repositories. Teams can ask who and what can reach the repo-server and Redis. Argo CD's documentation, quoted by Synacktiv, says secrets that plugins add are available to anyone with access to either.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Synacktiv.