As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.
github.com/argoproj/argo-cd/util/cache
{ "nvd_published_at": "2020-04-08T20:15:00Z", "cwe_ids": [ "CWE-307" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-07-26T21:13:31Z" }