Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Maximum severity Argo CD API Dosha Leak Repository Credit
    Security

    Maximum severity Argo CD API Dosha Leak Repository Credit

    PineapplesUpdateBy PineapplesUpdateSeptember 6, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Maximum severity Argo CD API Dosha Leak Repository Credit
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Maximum severity Argo CD API Dosha Leak Repository Credit

    An Argo CD vulnerability allows API tokens, even the API with low project-level allows to reach the closing points and regain all the repository credentials associated with the project.

    Defended, tracked under Cve-2025-55190The CVSS V3 rates the maximum severity of 10.0 with a score, and allows to bypass the separation mechanisms used to protect sensitive credential information.

    The attackers holding those credentials can then use them to clones private codebase, inject malicious manifests, try to compromise a downstream compromise, or use pivot for other resources where similar credentials are reused.

    Argo CD is a Kubernets-Environment Continuous Periny (CD) and GITOPS tools used by many organizations, including large enterprises such as Adobe, Google, IBM, INTUIT, RED HAT, Capital One and Blackrock, which use it to handle large scale, to handle a large scale.

    The newly discovered vulnerability affects all versions of the Argo CD to 2.13.0.

    “Argo CD API token with project-level permissions The project details API are capable of reclaiming sensitive repository credentials (user names, passwords) through API Closing Point, even when the tokens only have only standard application management permissions and no clear access to mystery,” Bulletin reads Published on Project’s Github.

    “API tokens must require clear permission to access sensitive credential information,” adds the bulletin to another part, given that “standard project permissions should not provide access to repository secrets.”

    Disclosure indicates that low-level tokens can retrieve user names and passwords of a repository.

    The attack still requires a valid Argo CD API token, so it is not exploited by informal users. However, low-authorized users can use them to get access to sensitive data that should not usually be accessible.

    “This vulnerability not only affects project-level permissions. Any token with the project is also weak, such as global permissions such as: P, Roll/User, Projects, Gate, Gate, *, allow,” Argo project has warned.

    Due to the detailed width of the low-considering tokens taking advantage of this defect, the opportunity for the danger actors to gain access to the tokens increases.

    Given the widespread deployment of Argo CD in production groups by major enterprises, direct credible exposure and low barrier for exploitation makes the defects particularly dangerous, possibly the code theft, forced recovery and leading to the supply chain attacks.

    Ashish Goyal discovered the CVE-2025-55190 blame, and it has been fixed It is recommended to transfer the administrators of the potentially affected systems to one of these versions as soon as possible in the Argo CD versions.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    API Argo credit Dosha leak maximum Repository severity
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAutomobylbranche Fortate Sicht Vor Cyberlacan
    Next Article AI’s ‘argument’ is not at all – how did this team remove industry publicity
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Amazon is selling the Meta Quest 3S for as little as $250 (and it comes with a free $50 credit)

    December 31, 2025
    Startups

    This popular Fitbit is $80 off, and comes with a $20 Amazon credit — here’s how to cash in

    November 3, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.