StackRadar

CVE-2024-36106

Medium

Advisory

Published 6 Jun 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
2 of 2
affected packages

Argo-cd authenticated users can enumerate clusters by name

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-cdgolangv1.5.82.9.171
github.com/argoproj/argo-cd/v2golangv2.4.7, v2.4.11, v2.7.2, v2.7.8+3 more2.9.177
OSV records
GHSA-3cqf-953p-h5cpGO-2024-2898
Also known as
BIT-argo-cd-2024-36106

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.9.17

Open the chart page →

3,793
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.9.17

Open the chart page →

10,315
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.9.17

Open the chart page →

5,039
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.9.17

Open the chart page →

5,039
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.9.17

Open the chart page →

13,450
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.9.17

Open the chart page →

2,607
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.9.17

Open the chart page →

5,039
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.17

Open the chart page →

2,314
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
2.9.17

Open the chart page →

6,671
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-36106.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.9.17

Open the chart page →

1,985

Container images carrying it

8 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.9.17
3
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.9.17
1
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
2.9.17
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.9.17
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.9.17
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.9.17
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.9.17
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.9.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.