Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8jc-jmrf-9h8f

Опубликовано: 26 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Argo CD Insecure default administrative password

In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.

Workaround:

The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password.

Пакеты

Наименование

github.com/argoproj/argo-cd

go
Затронутые версииВерсия исправления

<= 1.8.0

Отсутствует

EPSS

Процентиль: 62%
0.00429
Низкий

8.8 High

CVSS3

Дефекты

CWE-1188
CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.

EPSS

Процентиль: 62%
0.00429
Низкий

8.8 High

CVSS3

Дефекты

CWE-1188
CWE-287