CVE-2021-23347 - log back

CVE-2021-23347 edited at 03 Mar 2021 11:23:59
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 is vulnerable to Cross-site Scripting (XSS). The SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.
References
+ https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291
+ https://github.com/argoproj/argo-cd/pull/5563
+ https://github.com/argoproj/argo-cd/commit/31110cde4d72a78d1a9414d5e457f4d63223bce3
Notes
CVE-2021-23347 created at 03 Mar 2021 11:21:45