VDB
Sign up
HIGH

GHSA-c2hv-4pfj-mm2r

Argo Workflow may expose artifact repository credentials

Quick fix

GHSA-c2hv-4pfj-mm2r — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.

go get github.com/argoproj/argo-workflows/v3@v3.7.3

Details

### Summary An attacker who has permissions to read logs from pods in a namespace with Argo Workflow can read `workflow-controller` logs and get credentials to the artifact repository.

### Details An attacker, by reading the logs of the workflow controller pod, can access the artifact repository, and steal, delete or modify the data that resides there. The `workflow-controller` logs show the credentials in plaintext.

<img width="1366" alt="screen" src="https://github.com/user-attachments/assets/5642b2be-edcf-4050-bf47-747d05352698" />

### Impact An attacker with access to pod logs in the `argo` namespace can extract plaintext credentials from the `workflow-controller` logs and gain access to the artifact repository. This can lead to: - Data exfiltration – theft of sensitive or proprietary artifacts - Data tampering – modification of workflows or artifacts - Data destruction – deletion of stored artifacts, leading to potential loss of critical data or pipeline failure

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/argoproj/argo-workflows/v3
Introduced in: 3.7.0Fixed in: 3.7.3
Fixgo get github.com/argoproj/argo-workflows/v3@v3.7.3
Go/github.com/argoproj/argo-workflows/v3
Introduced in: 0Fixed in: 3.6.12
Fixgo get github.com/argoproj/argo-workflows/v3@v3.6.12

References