CVE-2020-8827: High severity argoproj Argo CD vulnerability
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/argoproj/argo-cdto a version that resolves this vulnerability.Fixed in 1.5.1
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-8827.
What is the severity of CVE-2020-8827?
CVE-2020-8827 has a severity of 7.5 (high).
What is affected by CVE-2020-8827?
The Argo API, specifically version 1.5.0 and below, as well as the Linuxfoundation Argo Continuous Delivery.
What are the consequences of CVE-2020-8827?
Attackers can submit an unlimited number of authentication attempts without consequence.
How do I fix CVE-2020-8827?
Update Argo API to version 1.5.1 or later to implement anti-automation measures such as rate limiting, account lockouts, and other anti-bruteforce measures.