Vulnerability Description
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argoproj | Argo Cd | 1.5.0 |
Related Weaknesses (CWE)
References
- https://github.com/argoproj/argo-cd/commit/35a7350b7444bcaf53ee0bb11b9d8e3ae4b71PatchThird Party Advisory
- https://github.com/argoproj/argo-cd/pull/3215PatchThird Party Advisory
- https://www.soluble.ai/blog/argo-cves-2020Third Party Advisory
- https://github.com/argoproj/argo-cd/commit/35a7350b7444bcaf53ee0bb11b9d8e3ae4b71PatchThird Party Advisory
- https://github.com/argoproj/argo-cd/pull/3215PatchThird Party Advisory
- https://www.soluble.ai/blog/argo-cves-2020Third Party Advisory
FAQ
What is CVE-2020-11576?
CVE-2020-11576 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned ...
How severe is CVE-2020-11576?
CVE-2020-11576 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11576?
Check the references section above for vendor advisories and patch information. Affected products include: Argoproj Argo Cd.