CVE-2020-8827

HIGH

Argo CD < 1.5.0 - Unauthenticated Excessive Authentication Attempts

Title source: llm
STIX 2.1

Description

As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://github.com/argoproj/argo/releases
Exploit, Third Party Advisory x_refsource_misc
https://www.soluble.ai/blog/argo-cves-2020

Scores

CVSS v3 7.5
EPSS 0.0216
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-307
Status published
Products (2)
argoproj/argo-cd 0 - 1.5.1Go
argoproj/argo_cd < 1.5.0
Published Apr 08, 2020
Tracked Since Feb 18, 2026