8.8
CVSSv3

CVE-2020-8828

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 6.5 | VMScore: 980 | EPSS: 0.00503 | KEV: Not Included
Published: 08/04/2020 Updated: 21/11/2024

Vulnerability Summary

Default Admin Password Flaw in Argo CD v1.5.0: Insider Threat

As of v1.5.0, the default admin password for the argocd-server pod is set to the pod name. People with access to the cluster or logs could misuse this for privilege escalation because Argo has privileged roles. The main risk comes from a malicious insider. However, pod names are not secret and can appear in many places.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

argoproj argo cd