Issue 218: Three Argo CD API exploits, distributed identity for modern API security
Brief
This week, we have news of three separate API vulnerabilities within the popular cloud-native continuous deployment platform. We also have a report covering the views of Gartner on the current state of API security and an article on distributed identity as a key element of modern API security. Finally, we have a guide on how to use the Burp Suite Scanner module to scan REST APIs.
Vulnerability: Three Argo CD API exploits within two weeks
First up is an excellent article courtesy of Security Boulevard covering three separate API exploits within the Argo CD continuous deployment platform.
The first vulnerability (tracked as CVE-2023-22736 ) is a high-severity flaw that allowed the caller to effectively “break out” of their configured permitted namespaces.
