Required CVE Record Information
Description
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://github.com/argoproj/argo/releases x_transferred
- https://www.soluble.ai/blog/argo-cves-2020 x_transferred
- https://argoproj.github.io/argo-cd/security_considerations/ x_transferred