StackRadar

CVE-2024-31990

Medium

Advisory

Published 15 Apr 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 2
affected packages

Argo CD's API server does not enforce project sourceNamespaces

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-cd/v2golangv2.4.7, v2.4.11, v2.7.2, v2.7.8+2 more2.8.16, 2.9.126
github.com/argoproj/argo-cdgolangv1.5.8no fix listed1
OSV records
GHSA-2gvw-w6fj-7m3cGO-2024-2728
Also known as
BIT-argo-cd-2024-31990

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.8.16

Open the chart page →

10,315
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.16

Open the chart page →

5,039
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.16

Open the chart page →

5,039
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.8.16

Open the chart page →

13,450
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.8.16

Open the chart page →

2,607
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.16

Open the chart page →

5,039
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.12

Open the chart page →

2,314
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed

Open the chart page →

6,671
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-31990.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.8.16

Open the chart page →

1,985

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.8.16
3
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.12
1
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.8.16
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.8.16
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.8.16
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.8.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.