{"id":"GHSA-rg3g-4rw9-gqrp","summary":"Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations","details":"### Summary\nThe original fix for [GHSA-3v3m-wc6v-x4x3](https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3) is incomplete. argocd app diff --server-side-diff can still expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation.\n\nThe prior fix masks top-level Secret data in ServerSideDiff responses, but it does not fully sanitize Secret data stored inside the last-applied-configuration annotation. If a Secret was previously created or updated using client-side apply, that annotation may contain raw data, stringData, and sensitive annotations. These values can be shown in UI/CLI diffs.\n\n### Details\nThe ServerSideDiff endpoint returns ResourceDiff.TargetState / LiveState based on server-side dry-run output. Kubernetes server-side dry-run can return a full predicted live Secret object that carries forward existing live annotations, including:\n\nkubectl.kubernetes.io/last-applied-configuration\nFor Secrets created with client-side apply, that annotation can contain a JSON-serialized Secret manifest with sensitive values.\n\nThe masking path calls HideSecretData(target, live, ...). However, HideSecretData only rewrites the last-applied annotation on the second argument (live). In server-side diff, the first argument can be predictedLive, not a clean Git target. predictedLive can also contain kubectl.kubernetes.io/last-applied-configuration, so the first object’s embedded annotation can remain unmasked.\n\n### PoC\nCreate an app containing this Secret manifest:\n```yaml\napiVersion: v1\nkind: Namespace\nmetadata:\n  name: last-applied-secret-repro\n---\napiVersion: v1\nkind: Secret\nmetadata:\n  name: secret\n  namespace: last-applied-secret-repro\n  annotations:\n    app: test\n    token: SECRETVAL\ntype: Opaque\ndata:\n  password: U0VDUkVUVkFM\n  username: U0VDUkVUVkFM\n```\nCreate and Sync Argo App\n```yaml\napiVersion: argoproj.io/v1alpha1\nkind: Application\nmetadata:\n  name: last-applied-secret-repro\n  namespace: argocd\n  annotations:\n    argocd.argoproj.io/compare-options: ServerSideDiff=true,IncludeMutationWebhook=true\nspec:\n  project: default\n  destination:\n    server: https://kubernetes.default.svc\n    namespace: last-applied-secret-repro\n  source:\n    repoURL: https://github.com/YOUR_ORG/YOUR_REPO.git\n    targetRevision: HEAD\n    path: last-applied-secret-repro\n  syncPolicy:\n    automated:\n      prune: true\n      selfHeal: true\n    syncOptions:\n      - CreateNamespace=true\n      - ServerSideApply=true\n```\nRun argo cd app diff\n`argocd app diff last-applied-secret-repro --server-side-diff --exit-code=false`\n```\n❯ argocd app diff last-applied-secret-repro --server-side-diff --exit-code=false\n\n===== /Secret last-applied-secret-repro/secret ======\n10c10,11\n\u003c     kubectl.kubernetes.io/last-applied-configuration: '{\"apiVersion\":\"v1\",\"data\":{\"password\":\"++++++++\",\"username\":\"++++++++\"},\"kind\":\"Secret\",\"metadata\":{\"annotations\":{\"app\":\"test\",\"argocd.argoproj.io/tracking-id\":\"last-applied-secret-repro:/Secret:last-applied-secret-repro/secret\",\"token\":\"SECRETVAL\"},\"name\":\"secret\",\"namespace\":\"last-applied-secret-repro\"},\"type\":\"Opaque\"}'\n---\n\u003e     kubectl.kubernetes.io/last-applied-configuration: |\n\u003e       {\"apiVersion\":\"v1\",\"data\":{\"password\":\"U0VDUkVUVkFM\",\"username\":\"U0VDUkVUVkFM\"},\"kind\":\"Secret\",\"metadata\":{\"annotations\":{\"app\":\"test\",\"argocd.argoproj.io/tracking-id\":\"last-applied-secret-repro:/Secret:last-applied-secret-repro/secret\",\"token\":\"SECRETVAL\"},\"name\":\"secret\",\"namespace\":\"last-applied-secret-repro\"},\"type\":\"Opaque\"}\n```\nThe secret value can be seen inside the diff\n\n### Impact\nAuthenticated Argo CD users who can view application diffs may be able to read Secret values that should be masked.\n\nImpacted values include:\nSecret data embedded in kubectl.kubernetes.io/last-applied-configuration","aliases":["BIT-argo-cd-2026-45737","CVE-2026-45737","GO-2026-5618"],"modified":"2026-07-20T21:51:42.218558597Z","published":"2026-05-19T15:54:21Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-19T15:54:21Z","nvd_published_at":null,"cwe_ids":["CWE-200","CWE-212"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-rg3g-4rw9-gqrp"},{"type":"PACKAGE","url":"https://github.com/argoproj/argo-cd"}],"affected":[{"package":{"name":"github.com/argoproj/argo-cd/v3","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.2.0"},{"fixed":"3.2.12"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2.11","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rg3g-4rw9-gqrp/GHSA-rg3g-4rw9-gqrp.json"}},{"package":{"name":"github.com/argoproj/argo-cd/v3","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.3.0-rc1"},{"fixed":"3.3.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rg3g-4rw9-gqrp/GHSA-rg3g-4rw9-gqrp.json","last_known_affected_version_range":"\u003c= 3.3.9"}},{"package":{"name":"github.com/argoproj/argo-cd/v3","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.4.0-rc1"},{"fixed":"3.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rg3g-4rw9-gqrp/GHSA-rg3g-4rw9-gqrp.json","last_known_affected_version_range":"\u003c= 3.4.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}