forked from wolfi-dev/advisories
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathargo-cd-3.0.advisories.yaml
More file actions
166 lines (158 loc) · 4.95 KB
/
argo-cd-3.0.advisories.yaml
File metadata and controls
166 lines (158 loc) · 4.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
schema-version: 2.0.2
package:
name: argo-cd-3.0
advisories:
- id: CGA-4gpj-334g-vx7h
aliases:
- CVE-2025-29923
- GHSA-92cp-5422-2mw7
events:
- timestamp: 2025-05-10T06:14:53Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: bc8f670e81919c31
componentName: github.com/redis/go-redis/v9
componentVersion: v9.7.1
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-05-13T20:13:07Z
type: fixed
data:
fixed-version: 3.0.0-r2
- id: CGA-fmmm-q55g-qcqq
aliases:
- CVE-2025-22872
- GHSA-vvgc-356p-c3xw
events:
- timestamp: 2025-05-10T06:14:50Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: 0ecd92f3cc61ddf2
componentName: golang.org/x/net
componentVersion: v0.37.0
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-05-13T20:13:08Z
type: fixed
data:
fixed-version: 3.0.0-r2
- id: CGA-j593-44g4-33gf
aliases:
- CVE-2025-29786
- GHSA-93mq-9ffx-83m2
events:
- timestamp: 2025-05-10T06:14:54Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: b3e2fb683814e0db
componentName: github.com/expr-lang/expr
componentVersion: v1.16.9
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-05-13T20:13:09Z
type: fixed
data:
fixed-version: 3.0.0-r2
- id: CGA-p92r-6rcm-c9cr
aliases:
- CVE-2025-1767
- GHSA-3wgm-2gw2-vh5m
events:
- timestamp: 2025-05-10T06:14:52Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: aeccd354e94ae01f
componentName: k8s.io/kubernetes
componentVersion: v1.32.2
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-05-13T12:42:06Z
type: false-positive-determination
data:
type: vulnerable-code-not-included-in-package
note: This vulnerability applies to the git-repo volume provisioner, not the k8s client itself.
- id: CGA-r9fv-v9h9-p5p5
aliases:
- CVE-2025-4563
- GHSA-hj2p-8wj8-pfq4
events:
- timestamp: 2025-06-24T08:08:49Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: 307de1d6c90a8db2
componentName: k8s.io/kubernetes
componentVersion: v1.32.2
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-06-24T09:48:15Z
type: fixed
data:
fixed-version: 3.0.6-r2
- id: CGA-w2xj-jv58-xrqm
aliases:
- GHSA-2x5j-vhc8-9cwm
events:
- timestamp: 2025-06-11T07:41:59Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: f23e388580842263
componentName: github.com/cloudflare/circl
componentVersion: v1.6.0
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-06-11T09:40:39Z
type: true-positive-determination
data:
note: Unable to use govulncheck to triage this advisory because the vulnerability was not found in the Go vuln DB. Treating as a true positive since we can't confirm this is a false positive.
- timestamp: 2025-06-11T09:46:08Z
type: fixed
data:
fixed-version: 3.0.6-r1
- id: CGA-wvr3-qqfv-67h5
aliases:
- GHSA-274v-mgcv-cm8j
events:
- timestamp: 2025-05-10T06:14:51Z
type: detection
data:
type: scan/v1
data:
subpackageName: argo-cd-3.0
componentID: 3a4329498bd23d66
componentName: github.com/argoproj/gitops-engine
componentVersion: v0.7.1-0.20250314164314-7258614f5041
componentType: go-module
componentLocation: /usr/local/bin/argocd
scanner: grype
- timestamp: 2025-05-13T12:27:59Z
type: false-positive-determination
data:
type: component-vulnerability-mismatch
note: |
The fixed version of GitOps Engine was integrated before 2.14
released in
https://github.com/argoproj/argo-cd/commit/d59c85c5eb55d5ccba3ef5ce6624306a1113ce00