#VU89007 Security features bypass in Argo CD - CVE-2024-21652
Published: April 25, 2024
Argo CD
Argo
Description
The vulnerability allows a remote attacker to bypass brute-force protection.
The vulnerability exists due to an error when handling different application states. A remote attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection.