VDB
Sign up
MEDIUM

GHSA-rc7p-gmvh-xfx2

Attack on Kubernetes via Misconfigured Argo Workflows

Details

### Impact

Users running using the Argo Server with `--auth-mode=server` (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining.

### Resolution

* Do not expose your user interface to the Internet. * Change configuration. `--auth-mode=client`.

For users using an older 2.x version of Argo Server, consider upgrading to Argo Server version 3.x or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/argoproj/argo-workflows
Introduced in: 0

No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.

References