POLICY-OTHER --
POLICY-OTHER ArgoCD Kubernetes ServerSideDiff potential secrets disclosure attempt
This rule looks for traffic to ArgoCD web applications' ServerSideDiff endpoint that contains objects of kind "Secret".
This rule alerts on attempts to perform a ServerSideDiff on sensitive information via ArgoCD web applications.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Information Leak
Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.
CVE-2026-42880 |
Loading description
|