As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
github.com/argoproj/argo-cd/util/cache
{
"severity": "HIGH",
"cwe_ids": [
"CWE-307"
],
"nvd_published_at": "2020-04-08T20:15:00Z",
"github_reviewed_at": "2021-07-26T21:13:31Z",
"github_reviewed": true
}