CVE-2020-8828
HIGH8.8EPSS 0.43%Argo CD Insecure default administrative password
描述
In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. #### Workaround: The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then [disabled](https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#disable-admin-user) or at least changed to a more secure password.
受影響套件(2)
- Bitnami/argo-cdfrom 0, < 1.5.0
- Go/github.com/argoproj/argo-cdfrom 0, <= 1.8.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-8828
- PATCHhttps://github.com/argoproj/argo-cd
- WEBhttps://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8828-insecure-default-administrative-password
- WEBhttps://argoproj.github.io/argo-cd/security_considerations
- WEBhttps://argoproj.github.io/argo-cd/security_considerations/
- WEBhttps://github.com/argoproj/argo-cd/blob/129cf5370f9e2c6f99c9a5515099250a7ba42099/docs/security_considerations.md#cve-2020-8828---insecure-default-administrative-password
- WEBhttps://github.com/argoproj/argo/releases
- WEBhttps://www.soluble.ai/blog/argo-cves-2020