PT-2020-20309 · Intuit · Argo

Published

2020-04-08

·

Updated

2024-08-07

·

CVE-2020-8826

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Argo versions 1.5.0 and later
Description The Argo web interface authentication system issued immutable tokens as of version 1.5.0. These authentication tokens, once issued, were usable forever without expiration, and there was no refresh or forced re-authentication.
Recommendations For versions 1.5.0 and later, consider implementing a token expiration mechanism or forced re-authentication to minimize the risk of exploitation. As a temporary workaround, restrict access to sensitive areas of the web interface until a more permanent solution is implemented.

Exploit

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

BIT-ARGO-CD-2020-8826
CVE-2020-8826

Affected Products

Argo