GHSA-6c73-2v8x-qpvm

    Dashboard / Vulnerabilities / GHSA-6c73-2v8x-qpvm

    GHSA-6c73-2v8x-qpvm

    Published: 23 Aug 2021Last Modified: 21 Aug 2024
    Aliases:

    Summary: Argo Server TLS requests could be forged by attacker with network access

    Details: ### Impact We are not aware of any exploits. This is a pro-active fix. Impacted: * You are running Argo Server < v3.0 with `--secure=true` or >= v3.0 with `--secure` unspecified (note - running in secure mode is recommended regardless). * The attacker is within your network. If you expose Argo Server to the Internet then "your network" is "the Internet". The Argo Server's keys are packaged within the image. They could be extracted and used to decrypt traffic, or forge requests. ### Patches https://github.com/argoproj/argo-workflows/pull/6540 ### Workarounds * Make sure that your Argo Server service or pod are not directly accessible outside of your cluster. Put TLS load balancer in front of it. This was identified by engineers at Jetstack.io

    Affected packages

    Package

    Name: github.com/argoproj/argo-workflows/v3

    Purl: pkg:golang/github.com/argoproj/argo-workflows/v3

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.0.0
    Fixed -3.0.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6c73-2v8x-qpvm | CVE-DB