Skip to content

Commit

Permalink
Fixing nitpick
Browse files Browse the repository at this point in the history
  • Loading branch information
Srivaralakshmi committed Jan 31, 2024
1 parent 66fb101 commit c628cdd
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 0 deletions.
1 change: 1 addition & 0 deletions modules/gitops-release-notes-1-10-2.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
The following issue has been resolved in the current release:

* Before this update, all versions of Argo CD `v2.8.3` and later were vulnerable to cross-server request forgery (CSRF) attacks. As a result, Argo CD would accept non-GET requests even if they did not specify their content type. This update fixes the issue by upgrading the Argo CD to `v.2.8.9` and patching this vulnerability in the Argo CD API.

[IMPORTANT]
====
Breaking change: The Argo CD API will no longer accept non-GET requests that do not specify application or JSON as their content type. Although the accepted content types list is configurable, do not disable the content type check completely.
Expand Down
1 change: 1 addition & 0 deletions modules/gitops-release-notes-1-9-4.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
The following issue has been resolved in the current release:

* Before this update, all versions of Argo CD `v2.7.2` and later were vulnerable to cross-server request forgery (CSRF) attacks. As a result, Argo CD would accept non-GET requests even if they did not specify their content type. This update fixes the issue by upgrading the Argo CD to `v.2.7.16` and patching this vulnerability in the Argo CD API.

[IMPORTANT]
====
Breaking change: The Argo CD API will no longer accept non-GET requests that do not specify application or JSON as their content type. Although the accepted content types list is configurable, do not disable the content type check completely.
Expand Down

0 comments on commit c628cdd

Please sign in to comment.