Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcqr-9h24-vrgw

Опубликовано: 26 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Restriction of Excessive Authentication Attempts in Argo API

As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.

Specific Go Packages Affected

github.com/argoproj/argo-cd/util/cache

Пакеты

Наименование

github.com/argoproj/argo-cd

go
Затронутые версииВерсия исправления

< 1.5.1

1.5.1

EPSS

Процентиль: 72%
0.00714
Низкий

7.5 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.

EPSS

Процентиль: 72%
0.00714
Низкий

7.5 High

CVSS3

Дефекты

CWE-307