CVE-2020-8827
08.04.2020, 20:15
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.Enginsight
Vendor | Product | Version |
---|---|---|
argoproj | argo_cd | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
References