#VU27018 Improper Authentication in Argo CD - CVE-2020-8827
Published: April 20, 2020
Argo CD
Argo
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. A remote attacker can submit an unlimited number of authentication attempts without consequence, bypass authentication process and gain unauthorized access to the application.