Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Argo 授权问题漏洞
Vulnerability Description
Argo是一款开源的容器本机工作流引擎。 Argo v1.5.0之前版本中存在授权问题漏洞,该漏洞源于程序将默认的管理员密码设置为argocd-server容器组名。攻击者可借助特制请求利用该漏洞获取管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A