CVE-2020-8828

As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:argo_continuous_delivery:*:*:*:*:*:kubernetes:*:*

Information

Published : 2020-04-08 13:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-8828

Mitre link : CVE-2020-8828


JSON object : View

CWE
CWE-287

Improper Authentication

CWE-1188

Insecure Default Initialization of Resource

Advertisement

dedicated server usa

Products Affected

linuxfoundation

  • argo_continuous_delivery