CVE-2020-11576: Medium severity argo cd vulnerability
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-11576?
CVE-2020-11576 is a user-enumeration vulnerability in Argo version 1.5.0 that allows attackers to determine the usernames of valid non-SSO accounts.
What is the severity of CVE-2020-11576?
CVE-2020-11576 has a severity level of medium with a CVSS score of 5.3.
How can I fix CVE-2020-11576?
To fix CVE-2020-11576, update to Argo version 1.5.1, which contains the necessary security fixes.
Which packages are affected by CVE-2020-11576?
CVE-2020-11576 affects the Argo Continuous Delivery package version 1.5.0 and the Argo CD package versions 1.5.0.
Are there any references for CVE-2020-11576?
Yes, you can find references for CVE-2020-11576 at the following links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-11576), [Argo CD Pull Request](https://github.com/argoproj/argo-cd/pull/3215), [Argo CD Commit](https://github.com/argoproj/argo-cd/commit/35a7350b7444bcaf53ee0bb11b9d8e3ae4b717a1).