MEDIUM
GHSA-rc7p-gmvh-xfx2
Attack on Kubernetes via Misconfigured Argo Workflows
Details
### Impact
Users running using the Argo Server with `--auth-mode=server` (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining.
### Resolution
* Do not expose your user interface to the Internet. * Change configuration. `--auth-mode=client`.
For users using an older 2.x version of Argo Server, consider upgrading to Argo Server version 3.x or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/argoproj/argo-workflows
Introduced in:
0No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.