All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
{
"versions": [
{
"introduced": "0.5.0"
},
{
"last_affected": "2.1.12"
},
{
"introduced": "2.2.0"
},
{
"last_affected": "2.2.7"
},
{
"introduced": "2.3.0"
},
{
"last_affected": "2.3.1"
}
]
}