PT-2022-19423 · Unknown · Kubernetes+2
Alexec
·
Published
2022-05-05
·
Updated
2026-02-06
·
CVE-2022-29164
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Argo Workflows versions prior to the fixed version
Description
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions, an attacker can create a workflow that produces a HTML artifact containing an HTML file with a script using XHR calls to interact with the
Argo Server API. The attacker emails a deep-link to the artifact to the victim, who, upon opening the link, allows the script to run. With access to the Argo Server API as the victim, the script may read information about the victim's workflows or create and delete workflows. The attacker must be an insider with access to the same cluster as the victim and must already be able to run their own workflows. They must also have an understanding of the victim's system. There is no evidence of this issue being exploited in the wild.Recommendations
As a temporary workaround, consider disabling the Argo Server until a patch is available.
Upgrade to the fixed version to resolve the issue.
Note that disabling the Argo Server is currently the only known workaround, and no fix is planned for version 2.12, which has been out of support for some time.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Argo Server
Argo Workflows
Kubernetes