Filtered by vendor Argoproj Subscriptions
Total 62 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-11576 1 Argoproj 1 Argo Cd 2024-11-21 5.3 Medium
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.
CVE-2018-21034 1 Argoproj 1 Argo Cd 2024-11-21 6.5 Medium
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.