Is Argo CD 1.2.5 patched?
Current stable (3.4.3): 100/100
1.2.5 has 18 open critical-or-high vulnerabilities. Run 2.14.20 or later to clear them. See what 2.14.20 fixes →
Summary iPlain-English security status for Argo CD 1.2.5, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Argo CD 1.2.5 is part of the 1.2 release line. 29 known vulnerabilities affect it. The minimum safe version is 2.14.20 — upgrade to it or later to clear the open critical/high issues. The 1.2 line reached end-of-life on 2020-01-18, so it no longer receives security patches. The latest supported Argo CD release is 3.4.3.
Known issues affecting 1.2.5
Exploited first, then by exploitation probability.
CVE-2022-24348 HIGH EPSS 3% → fixed in 2.2.4 CVE-2020-8827 HIGH EPSS 2% → fixed in 1.5.0 CVE-2020-8828 HIGH EPSS 2% → fixed in 1.5.0 CVE-2020-8826 HIGH EPSS 2% → see advisory CVE-2024-31989 CRITICAL EPSS 1% → fixed in 2.11.1 CVE-2021-26923 HIGH EPSS 1% → fixed in 1.8.4 CVE-2024-40634 HIGH EPSS 1% → fixed in 2.11.6 CVE-2018-21034 MEDIUM EPSS 1% → see advisory CVE-2021-26921 MEDIUM EPSS 1% → fixed in 1.8.4 CVE-2022-24768 CRITICAL EPSS 1% → fixed in 2.3.2 CVE-2022-24905 MEDIUM EPSS 1% → fixed in 2.3.4 CVE-2024-21661 HIGH EPSS 1% → fixed in 2.10.4 CVE-2022-1025 HIGH EPSS 1% → see advisory CVE-2022-24904 MEDIUM EPSS 1% → fixed in 2.3.4 CVE-2024-21662 HIGH EPSS 1% → fixed in 2.10.4 CVE-2022-31034 HIGH EPSS 1% → fixed in 2.1.16 CVE-2022-31035 CRITICAL EPSS 1% → fixed in 2.1.16 CVE-2022-31016 MEDIUM EPSS 1% → fixed in 2.4.1 CVE-2024-21652 CRITICAL EPSS 1% → fixed in 2.10.4 CVE-2021-26924 MEDIUM EPSS 1% → fixed in 1.8.4Other Argo CD versions
Check another release line of Argo CD.
Frequently asked
Is Argo CD 1.2.5 patched?
Argo CD 1.2.5 is end-of-life and no longer receives security patches. Move to 3.4.3.
What version should I upgrade Argo CD 1.2.5 to?
Upgrade Argo CD 1.2.5 to at least 2.14.20 to clear its 18 open critical-or-high vulnerabilities.
When does Argo CD 1.2 reach end-of-life?
Argo CD 1.2 reached end-of-life on 2020-01-18 and no longer receives security patches.
What is the latest version of Argo CD?
The latest supported Argo CD release is 3.4.3.
Is Argo CD 1.2.5 still receiving security updates?
No — Argo CD 1.2.5 is on the 1.2 line, which reached end-of-life on 2020-01-18 and no longer receives security updates. Upgrade to 3.4.3 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Argo Project's official advisory before you patch or upgrade — Argo CD official site ↗