Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Go

Improper Restriction of Excessive Authentication Attempts in Argo API

GHSA-xcqr-9h24-vrgw · BIT-argo-cd-2020-8827 · CVE-2020-8827 · GO-2022-0892

Published · Modified

Description

As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.

Specific Go Packages Affected

github.com/argoproj/argo-cd/util/cache

Ready to move

Start Securing

Free, no credit card | First findings in minutes