PT-2020-20309 · Intuit · Argo
Published
2020-04-08
·
Updated
2024-08-07
·
CVE-2020-8826
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Argo versions 1.5.0 and later
Description
The Argo web interface authentication system issued immutable tokens as of version 1.5.0. These authentication tokens, once issued, were usable forever without expiration, and there was no refresh or forced re-authentication.
Recommendations
For versions 1.5.0 and later, consider implementing a token expiration mechanism or forced re-authentication to minimize the risk of exploitation. As a temporary workaround, restrict access to sensitive areas of the web interface until a more permanent solution is implemented.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Argo