/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-32476

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-32476

Severity

6.5

Medium

CVSS V3

Summary

Denial of Service via malicious jqPathExpressions in ignoreDifferences

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing