In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/argoproj/argo-cd/commit/f5b0db240b4e3abf18e97f6fd99096b4f9e94dc5 | Patch Third Party Advisory | 
| https://github.com/argoproj/argo-cd/compare/v1.8.3...v1.8.4 | Patch Third Party Advisory | 
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-9h6w-j7w4-jr52 | Third Party Advisory | 
| https://github.com/argoproj/argo-cd/commit/f5b0db240b4e3abf18e97f6fd99096b4f9e94dc5 | Patch Third Party Advisory | 
| https://github.com/argoproj/argo-cd/compare/v1.8.3...v1.8.4 | Patch Third Party Advisory | 
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-9h6w-j7w4-jr52 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 05:57
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/argoproj/argo-cd/commit/f5b0db240b4e3abf18e97f6fd99096b4f9e94dc5 - Patch, Third Party Advisory | |
| References | () https://github.com/argoproj/argo-cd/compare/v1.8.3...v1.8.4 - Patch, Third Party Advisory | |
| References | () https://github.com/argoproj/argo-cd/security/advisories/GHSA-9h6w-j7w4-jr52 - Third Party Advisory | 
07 Aug 2024, 15:43
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
| First Time | Argoproj argo Cd Argoproj | 
Information
                Published : 2021-02-09 15:15
Updated : 2024-11-21 05:57
NVD link : CVE-2021-26921
Mitre link : CVE-2021-26921
CVE.ORG link : CVE-2021-26921
JSON object : View
Products Affected
                argoproj
- argo_cd
CWE
                
                    
                        
                        CWE-613
                        
            Insufficient Session Expiration
