Blog Viewer

Argo CD fix for critical CVE-2025-47933

By Beltran Rueda Borrego posted May 29, 2025 04:00 AM

  

The Argo CD project just released new versions of all the supported branches for fixing a critical security issue, CVE-2025-47933 Argo CD allows cross-site scripting on repositories page. This vulnerability allows an attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, and deleting Kubernetes resources. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository.

The Argo CD project has already released fixed versions for the Argo CD UI: 

  • v3.0.4
  • v2.14.13
  • v2.13.8

Tanzu Application Catalog already built from source, verified and released all the supported versions and supported Linux distributions in less than 2h.

The Bitnami Helm chart was already released v9.0.12 with the container image update after the official release and customers. Bitnami Open Source users,  Bitnami Premium and Tanzu Application Catalog customers are able to upgrade their installations in a simple way via Helm.
0 comments
21 views

Permalink