CVE detail
CVE-2020-11576 — CVE-2020-11576
Published 2020-04-08 · Modified 2026-06-17 · Vendor argoproj · Product argo_cd · Source nvd
MEDIUM
severity
CVSS-derived band
0.0192
EPSS probability
exploitation probability, 30d
78.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References