Token Mismanagement in Argo CD by Argo Project
CVE-2021-26921

6.5MEDIUM

Key Information:

Vendor
Linux
Vendor
CVE Published:
9 February 2021

Summary

In Argo CD versions prior to 1.8.4, a vulnerability exists where authentication tokens remain valid even if the associated user account is disabled. This oversight can lead to unauthorized access, allowing individuals to continue using the tokens despite their account being inactive. Organizations using affected versions are at risk if user accounts are disabled without revoking their associated tokens, potentially exposing sensitive operations to compromised or malicious actors.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.