Fiche vulnérabilité
CVE-2020-8826 : faille élevée argoproj argo cd (CVSS 7.5)
Description
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 8 avr. 2020
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- argoproj argo cd