PT-2020-20311 · Intuit · Argo Cd

Matt Hamilton

·

Published

2020-04-08

·

Updated

2024-08-07

·

CVE-2020-8828

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Argo CD versions 1.5.0 through 1.8.0
Description The default admin password is set to the argocd-server pod name, which could be abused for privilege escalation by insiders with access to the cluster or logs, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
Recommendations For versions 1.5.0 through 1.8.0, use SSO integration as a mitigation measure. The default admin password should only be used for initial configuration and then disabled or at least changed to a more secure password. Consider disabling the default admin user or changing its password to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-ARGO-CD-2020-8828
CVE-2020-8828
GHSA-H8JC-JMRF-9H8F

Affected Products

Argo Cd