Unauthorized access to Argo dashboard on █████
Medium
Vulnerability Details
##Summary
Hi team i hope you are well t is a pleasure to work in your program. I will begin to present the vulnerability that I found it: Unauthorized access to Argo dashboard
After conducting an in-depth analysis, I have identified a security concern within the Argo deployment to which I have access. Specifically, I can manipulate workflows, including deletion and addition, as well as modify sensors. While the immediate impact is assessed as low, it is important to acknowledge that this vulnerability could potentially lead to unauthorized access and compromise sensitive data in future deployments. Urgent attention and corrective measures are advised to mitigate this risk and ensure the security of the system.
##Steps
Vulnerable subdomain :
```
1. https://████/
```
###Example POC: https://█████/
███
███████
███████
## Impact
Leads to information disclosure
## System Host(s)
██████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Go to the webisite below:
https://████████/workflows
## Suggested Mitigation/Remediation Actions
Block access to dashboard
Actions
View on HackerOneReport Stats
- Report ID: 2247231
- State: Closed
- Substate: resolved
- Upvotes: 10