Default Admin Password Flaw in Argo CD v1.5.0: Insider Threat
As of v1.5.0, the default admin password for the argocd-server pod is set to the pod name. People with access to the cluster or logs could misuse this for privilege escalation because Argo has privileged roles. The main risk comes from a malicious insider. However, pod names are not secret and can appear in many places.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
argoproj argo cd |