{"id":"GHSA-h8jc-jmrf-9h8f","summary":"Argo CD Insecure default administrative password","details":"In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.\n\n#### Workaround:\n\nThe recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then [disabled](https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#disable-admin-user) or at least changed to a more secure password.","aliases":["BIT-argo-cd-2020-8828","CVE-2020-8828"],"modified":"2024-08-07T19:44:16Z","published":"2021-07-26T21:19:27Z","database_specific":{"nvd_published_at":"2020-04-08T20:15:00Z","cwe_ids":["CWE-1188","CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-07-26T21:14:45Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8828"},{"type":"WEB","url":"https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8828-insecure-default-administrative-password"},{"type":"WEB","url":"https://argoproj.github.io/argo-cd/security_considerations"},{"type":"PACKAGE","url":"https://github.com/argoproj/argo-cd"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/blob/129cf5370f9e2c6f99c9a5515099250a7ba42099/docs/security_considerations.md#cve-2020-8828---insecure-default-administrative-password"},{"type":"WEB","url":"https://github.com/argoproj/argo/releases"},{"type":"WEB","url":"https://www.soluble.ai/blog/argo-cves-2020"}],"affected":[{"package":{"name":"github.com/argoproj/argo-cd","ecosystem":"Go","purl":"pkg:golang/github.com/argoproj/argo-cd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-h8jc-jmrf-9h8f/GHSA-h8jc-jmrf-9h8f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}