CVE-2021-26921

MEDIUM

Argoproj Argo CD < 1.7.12 - Insufficient Session Expiration

Title source: rule
STIX 2.1

Description

In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

References (3)

Core 3

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-613
Status published
Products (1)
argoproj/argo_cd < 1.7.12
Published Feb 09, 2021
Tracked Since Feb 18, 2026