Authentication Vulnerability in Argo API by Argo Project
CVE-2020-8827
7.5HIGH
What is CVE-2020-8827?
The Argo API starting from version 1.5.0 lacks essential anti-automation measures such as rate limiting and account lockouts. This oversight allows attackers to execute unlimited authentication attempts, increasing the risk of unauthorized access through brute force attacks. Implementing security controls is crucial to mitigate the risk associated with this vulnerability.