GHSA-x32m-mvfj-52xv · Severity: critical · Ecosystem: go — Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the brute force login protection mechanism. Not only can they crash the service affecting all users, but they can also make unlimited login attempts, increasing the risk of account compromise. Versions 2.8.13, 2.9.9, and 2.10.4 contain a patch for this issue.
Conclusion & alert: CVE-2024-21652 is rated Moderate Risk (57.4/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.75%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.07% | 0.75% | +0.69% |
| 2 | 2025-11-21 | 0.41% | 0.07% | -0.34% |
| 3 | 2025-11-18 | — | 0.41% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-x32m-mvfj-52xv · Severity: critical · Ecosystem: go — Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2024-21652 |
| URL | Tags |
|---|---|
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-x32m-mvfj-52xv | Vendor Advisory |