Unauthorized access to Argo dashboard on █████

Disclosed: 2023-12-21 17:34:28 By devdevrl To deptofdefense
Medium
Vulnerability Details
##Summary Hi team i hope you are well t is a pleasure to work in your program. I will begin to present the vulnerability that I found it: Unauthorized access to Argo dashboard After conducting an in-depth analysis, I have identified a security concern within the Argo deployment to which I have access. Specifically, I can manipulate workflows, including deletion and addition, as well as modify sensors. While the immediate impact is assessed as low, it is important to acknowledge that this vulnerability could potentially lead to unauthorized access and compromise sensitive data in future deployments. Urgent attention and corrective measures are advised to mitigate this risk and ensure the security of the system. ##Steps Vulnerable subdomain : ``` 1. https://████/ ``` ###Example POC: https://█████/ ███ ███████ ███████ ## Impact Leads to information disclosure ## System Host(s) ██████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Go to the webisite below: https://████████/workflows ## Suggested Mitigation/Remediation Actions Block access to dashboard
Actions
View on HackerOne
Report Stats
  • Report ID: 2247231
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report