API Vulnerability in Argo Affecting User Data Exposure
CVE-2018-21034
6.5MEDIUM
Summary
In Argo versions before v1.5.0-rc1, an API vulnerability allowed authenticated users to execute unauthorized API requests. This could lead to the retrieval of sensitive secrets and other confidential manifests saved within git repositories, potentially compromising user data and application configurations.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved