As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://github.com/argoproj/argo/releases | third party advisory |
https://www.soluble.ai/blog/argo-cves-2020 | third party advisory exploit |
https://argoproj.github.io/argo-cd/security_considerations/ | vendor advisory |
https://argoproj.github.io/argo-cd/operator-manual/user-management/#disable-admin-user | vendor advisory |