Skip to content

Commit fb7b899

Browse files
thatnealpatelgopherbot
authored andcommitted
data/reports: update GO-2025-3427
- data/reports/GO-2025-3427.yaml Updates #3427 Updates #3464 Change-Id: Ibfb17adc86b1ac85c5182d93a84abfbbe5b465bd Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/657635 Reviewed-by: Zvonimir Pavlinovic <[email protected]> LUCI-TryBot-Result: Go LUCI <[email protected]> Auto-Submit: Neal Patel <[email protected]>
1 parent 4c78870 commit fb7b899

File tree

2 files changed

+6
-27
lines changed

2 files changed

+6
-27
lines changed

data/osv/GO-2025-3427.json

Lines changed: 3 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -7,29 +7,12 @@
77
"CVE-2024-13484",
88
"GHSA-58fx-7v9q-3g56"
99
],
10-
"summary": "ArgoCD Namespace Isolation Break in github.com/argoproj/argo-cd",
11-
"details": "ArgoCD Namespace Isolation Break in github.com/argoproj/argo-cd",
10+
"summary": "Malicious PrometheusRule creation to all namespaces that deploy a ArgoCD CR instance in github.com/redhat-developer/gitops-operator",
11+
"details": "Malicious PrometheusRule creation to all namespaces that deploy a ArgoCD CR instance in github.com/redhat-developer/gitops-operator",
1212
"affected": [
1313
{
1414
"package": {
15-
"name": "github.com/argoproj/argo-cd",
16-
"ecosystem": "Go"
17-
},
18-
"ranges": [
19-
{
20-
"type": "SEMVER",
21-
"events": [
22-
{
23-
"introduced": "0"
24-
}
25-
]
26-
}
27-
],
28-
"ecosystem_specific": {}
29-
},
30-
{
31-
"package": {
32-
"name": "github.com/argoproj/argo-cd/v2",
15+
"name": "github.com/redhat-developer/gitops-operator",
3316
"ecosystem": "Go"
3417
},
3518
"ranges": [

data/reports/GO-2025-3427.yaml

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,8 @@
11
id: GO-2025-3427
22
modules:
3-
- module: github.com/argoproj/argo-cd
4-
vulnerable_at: 1.8.6
5-
- module: github.com/argoproj/argo-cd/v2
6-
unsupported_versions:
7-
- last_affected: 2.10.3
8-
vulnerable_at: 2.13.3
9-
summary: ArgoCD Namespace Isolation Break in github.com/argoproj/argo-cd
3+
- module: github.com/redhat-developer/gitops-operator
4+
vulnerable_at: 1.15.0
5+
summary: Malicious PrometheusRule creation to all namespaces that deploy a ArgoCD CR instance in github.com/redhat-developer/gitops-operator
106
cves:
117
- CVE-2024-13484
128
ghsas:

0 commit comments

Comments
 (0)