A newly disclosed vulnerability in Argo CD's repo-server component allows unauthenticated attackers to execute remote code and potentially take over Kubernetes clusters. The flaw, which affects the GenerateManifest gRPC…
Jakub Ciolek reported two denial-of-service vulnerabilities in Argo CD through HackerOne's Internet Bug Bounty program last fall. Although both vulnerabilities were assigned CVEs and fixed, Ciolek states he did not…