QID 981989
QID 981989: Go (go) Security Update for github.com/argoproj/argo-cd/util/cache (GHSA-xcqr-9h24-vrgw)
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xcqr-9h24-vrgw for updates pertaining to this vulnerability.
Vendor References
- GHSA-xcqr-9h24-vrgw -
github.com/advisories/GHSA-xcqr-9h24-vrgw
CVEs related to QID 981989
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xcqr-9h24-vrgw | github.com/argoproj/argo-cd/util/cache |
|