Vulnerabilities > CVE-2021-26921 - Insufficient Session Expiration vulnerability in Linuxfoundation Argo Continuous Delivery

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
linuxfoundation
CWE-613

Summary

In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

Vulnerable Configurations

Part Description Count
Application
Linuxfoundation
137

Common Weakness Enumeration (CWE)