Token Mismanagement in Argo CD by Argo Project
CVE-2021-26921
6.5MEDIUM
Summary
In Argo CD versions prior to 1.8.4, a vulnerability exists where authentication tokens remain valid even if the associated user account is disabled. This oversight can lead to unauthorized access, allowing individuals to continue using the tokens despite their account being inactive. Organizations using affected versions are at risk if user accounts are disabled without revoking their associated tokens, potentially exposing sensitive operations to compromised or malicious actors.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved