Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes.
As the script has access to the Argo Server API (as the victim), so may do the following (if the victim may):
Notes:
We have seen no evidence of this in the wild. While the impact is high, it is very hard to exploit.
We urge all users to upgrade to the fixed versions. Disabling the Argo Server is the only known workaround. Note version 2.12 has been out of support for sometime. No fix is currently planned.
{ "nvd_published_at": "2022-05-06T00:15:00Z", "github_reviewed_at": "2022-05-23T20:16:05Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-269" ] }