Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/argoproj/argo-cd
  4. ›
  5. GMS-2023-136

GMS-2023-136: JWT audience claim is not verified

January 25, 2023

All versions of Argo CD starting with v1.8.2 is vulnerable to an improper authorization bug causing the API to accept certain invalid tokens.

OIDC providers include an aud (audience) claim in signed tokens. The value of that claim specifies the intended audience(s) of the token (i.e. the service or services which are meant to accept the token).

References

  • github.com/advisories/GHSA-q9hr-j4rf-8fjc
  • github.com/argoproj/argo-cd/security/advisories/GHSA-q9hr-j4rf-8fjc

Code Behaviors & Features

Detect and mitigate GMS-2023-136 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.8.2 before 2.3.14, all versions starting from 2.4.0 before 2.4.20, all versions starting from 2.5.0 before 2.5.8, all versions starting from 2.6.0-rc1 before 2.6.0-rc5

Fixed versions

  • v2.3.14
  • v2.4.20
  • v2.5.8
  • v2.6.0-rc5

Solution

Upgrade to versions 2.3.14, 2.4.20, 2.5.8, 2.6.0-rc5 or above. *Note*: 2.6.0-rc5 may be an unstable version. Use caution.

Source file

go/github.com/argoproj/argo-cd/GMS-2023-136.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:41 +0000.