CVE-2020-8826

HIGH

Argo CD < 1.5.0 - Session Fixation via Immutable Authentication Tokens

Title source: llm
STIX 2.1

Description

As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/argoproj/argo/releases
Exploit, Third Party Advisory x_refsource_misc
https://www.soluble.ai/blog/argo-cves-2020

Scores

CVSS v3 7.5
EPSS 0.0171
EPSS Percentile 74.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-384
Status published
Products (1)
argoproj/argo_cd < 1.5.0
Published Apr 08, 2020
Tracked Since Feb 18, 2026