CVE-2021-37914
Dashboard / Vulnerabilities / CVE-2021-37914
CVE-2021-37914
Published: 3 Aug 2021Last Modified: 9 Jul 2026
Summary:
Details: In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.
References: https://github.com/argoproj/argo-workflows/issues/6441, https://github.com/argoproj/argo-workflows/pull/6442
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
Affected versions
v3.1.3
v3.1.2
v3.1.1
v3.1.0
v3.1.0-rc14
v3.1.0-rc13
v3.1.0-rc12
v3.1.0-rc11
v3.1.0-rc10
v3.1.0-rc9
v3.1.0-rc8
v3.1.0-rc7
v3.1.0-rc6
v3.1.0-rc5
v3.1.0-rc4
v3.1.0-rc3
v3.1.0-rc2
v3.1.0-rc1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
