Vulnerabilities
Vulnerable Software
Argoproj:  Security Vulnerabilities
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
CVSS Score
7.5
EPSS Score
0.022
Published
2020-04-08
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
CVSS Score
8.8
EPSS Score
0.018
Published
2020-04-08
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.
CVSS Score
5.3
EPSS Score
0.019
Published
2020-04-08


Contact Us

Shodan ® - All rights reserved