Security Advisory
CVE-2020-8826
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.