Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/argocd-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/argo-rollouts-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/console-plugin-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/dex-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/gitops-operator-bundle:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/gitops-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/gitops-rhel8-operator:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/kam-delivery-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4972", "cpe": "cpe:/a:redhat:openshift_gitops:1.11::el8", "package": "openshift-gitops-1/must-gather-rhel8:v1.11.7-2", "product_name": "Red Hat OpenShift GitOps 1.11", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/argocd-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/argo-rollouts-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/console-plugin-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/dex-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/gitops-operator-bundle:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/gitops-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/gitops-rhel8-operator:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/kam-delivery-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el8", "package": "openshift-gitops-1/must-gather-rhel8:v1.12.5-5", "product_name": "Red Hat OpenShift GitOps 1.12", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4973", "cpe": "cpe:/a:redhat:openshift_gitops:1.12::el9", "package": "openshift-gitops-argocd-rhel9-container-v1.12.5-2", "product_name": "Red Hat OpenShift GitOps 1.12 - RHEL 9", "release_date": "2024-08-01T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/argocd-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/argo-rollouts-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/console-plugin-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/dex-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/gitops-operator-bundle:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/gitops-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/gitops-rhel8-operator:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/kam-delivery-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-1/must-gather-rhel8:v1.13.1-6", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}, {"advisory": "RHSA-2024:4891", "cpe": "cpe:/a:redhat:openshift_gitops:1.13::el8", "package": "openshift-gitops-argocd-rhel9-container-v1.13.1-1", "product_name": "Red Hat OpenShift GitOps 1.13", "release_date": "2024-07-26T00:00:00Z"}], "bugzilla": {"description": "argocd: Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in Argo CD", "id": "2299473", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2299473"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "status": "verified"}, "cwe": "CWE-400", "details": ["Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.", "A vulnerability was found in Argo CD. This flaw allows an unauthenticated attacker to send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation leading to service disruption by triggering an out-of-memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments."], "name": "CVE-2024-40634", "public_date": "2024-07-22T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2024-40634\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-40634\nhttps://github.com/argoproj/argo-cd/security/advisories/GHSA-jmvp-698c-4x3w"], "threat_severity": "Important"}