CVE-2021-23347

MEDIUM4.7EPSS 0.22%

Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd

Published: 5/21/2021Modified: 3/13/2026
Also known as:GHSA-qq5v-f4c3-395cBIT-argo-cd-2021-23347GO-2022-0869

Description

The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

References (4)