Логотип exploitDog
bind:CVE-2020-8828
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-8828

Количество 2

Количество 2

nvd логотип

CVE-2020-8828

почти 6 лет назад

As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-h8jc-jmrf-9h8f

больше 4 лет назад

Argo CD Insecure default administrative password

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-8828

As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-h8jc-jmrf-9h8f

Argo CD Insecure default administrative password

CVSS3: 8.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу