CVE-2026-42880
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.4 security update
Beschreibung
Argo CD ist ein deklaratives, GitOps-basiertes kontinuierliches Bereitstellungstool für Kubernetes. In den Versionen von 3.2.0 bis vor 3.2.11 und von 3.3.0 bis vor 3.3.9 gibt es eine Lücke im Bereich der Autorisierung und Datenmaskierung in Argo CDs ServerSideDiff-Endpunkt, die es einem Angreifer mit nur Lesezugriff ermöglicht, Klartextdaten von Kubernetes Secrets aus etcd über das Server-Side Apply Dry-Run-Mechanismus des Kubernetes API-Servers zu extrahieren. Dieses Problem wurde in den Versionen 3.2.11 und 3.3.9 behoben.
Metriken
Weakness-Klassen (CWE)
CWE-200Class
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
cwe.mitre.org →CWE-212Base
Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-07 13:19 UTC· security-advisories@github.com
- Reference: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3
- Reference: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3
- Reference Type: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 Types: Exploit, Vendor Advisory
- CVE Modified2026-09-07 13:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3
- Reference: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3
- Reference Type: https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 Types: Exploit, Vendor Advisory
- CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42880.json">CVE-2026-42880</a>
- Reference: https://access.redhat.com/errata/RHBA-2026:12433
- Reference: https://access.redhat.com/errata/RHSA-2026:20943
- Reference: https://access.redhat.com/errata/RHSA-2026:20947
- CVE Modified2026-08-11 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat OpenShift GitOps 1.19, Red Hat OpenShift GitOps 1.2, Red Hat OpenShift GitOps 1.2 (+8) → Red Hat OpenShift GitOps 1.19, Red Hat OpenShift GitOps 1.20, Red Hat OpenShift GitOps 1.20 (+8)
- CVE Modified2026-08-03 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat OpenShift GitOps 1.19, Red Hat OpenShift GitOps 1.2, Red Hat OpenShift GitOps 1.2 (+8) → Red Hat OpenShift GitOps 1.19, Red Hat OpenShift GitOps 1.2, Red Hat OpenShift GitOps 1.2 (+8)
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
bitnami
argo-cd3.2.0
bitnami
argo-cd3.3.0
bitnami
golang1.26.0-0
goxmldsig_project
goxmldsig1.6.0
grpc
grpc1.79.3
lodash
lodash4.0.0 – 4.18.0
lodash
lodash-amd4.0.0 – 4.18.0
lodash
lodash-es4.0.0 – 4.18.0
lodash
lodash.template4.0.0 – 4.18.0
Quellen & Referenzen
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851web
- https://security.netapp.com/advisory/ntap-20210312-0006/advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdffix
- https://www.oracle.com//security-alerts/cpujul2021.htmlfix
- https://www.oracle.com/security-alerts/cpujan2022.htmlfix
- https://www.oracle.com/security-alerts/cpujul2022.htmlfix
- https://www.oracle.com/security-alerts/cpuoct2021.htmlfix
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932evidence
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930evidence
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928evidence
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931evidence
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929evidence
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724evidence
- https://github.com/advisories/GHSA-35jh-r3h4-6jhm
- https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
- https://cna.openjsf.org/security-advisories.html
- https://access.redhat.com/security/cve/CVE-2026-4800vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2453496issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4800.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:42078vendor-advisoryx_refsource_REDHAT
Verknüpfte CVEs
- CVE-2026-4800
Auswirkungen: Die Behebung für CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) fügte eine Validierung für die Variabl…
criticalCVSSv3 9.8 - CVE-2026-33487
goxmlsig bietet XML-Digitale Signaturen, die in Go implementiert sind.
highCVSSv3 7.5 - CVE-2026-33186
gRPC-Go ist die Go-Sprachimplementierung von gRPC.
criticalCVSSv3 9.1 - CVE-2026-32281
Die Überprüfung von Zertifikatsketten, die Richtlinien verwenden, ist unerwartet ineffizient, wenn die Zertifikate in der Kette eine sehr…
highCVSSv3 7.5