ZeroHour

CVE-2020-8826

PoC
CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
Modified
Description

As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.

Vendors
argoproj
Products
argo cd
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.