Vulnerabilities > CVE-2021-26921 - Insufficient Session Expiration vulnerability in Argoproj Argo CD

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
argoproj
CWE-613

Summary

In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

Vulnerable Configurations

Part Description Count
Application
Argoproj
137

Common Weakness Enumeration (CWE)