GHSA-h8jc-jmrf-9h8f
Dashboard / Vulnerabilities / GHSA-h8jc-jmrf-9h8f
GHSA-h8jc-jmrf-9h8f
Summary: Argo CD Insecure default administrative password
Details: In Argo CD versions 1.8.0 and prior, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere. #### Workaround: The recommended mitigation as described in the user documentation is to use SSO integration. The default admin password should only be used for initial configuration and then [disabled](https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#disable-admin-user) or at least changed to a more secure password.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-8828, https://argo-cd.readthedocs.io/en/stable/security_considerations/#cve-2020-8828-insecure-default-administrative-password, https://argoproj.github.io/argo-cd/security_considerations, https://github.com/argoproj/argo-cd, https://github.com/argoproj/argo-cd/blob/129cf5370f9e2c6f99c9a5515099250a7ba42099/docs/security_considerations.md#cve-2020-8828---insecure-default-administrative-password, https://github.com/argoproj/argo/releases, https://www.soluble.ai/blog/argo-cves-2020
Affected packages
Package
Name: github.com/argoproj/argo-cd
Purl: pkg:golang/github.com/argoproj/argo-cd
Affected ranges
Type: SEMVER
Events:
