MEDIUM
GHSA-h563-xh25-x54q
Workflow re-write vulnerability using input parameter
Quick fix
GHSA-h563-xh25-x54q — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.
go get github.com/argoproj/argo-workflows/v3@v3.1.6Details
### Impact
* Allow end-users to set input parameters, but otherwise expect workflows to be secure.
### Patches
Not yet.
### Workarounds
* Set `EXPRESSION_TEMPLATES=false` for the workflow controller
### References
* https://github.com/argoproj/argo-workflows/issues/6441
### For more information If you have any questions or comments about this advisory: * Open an issue in [example link to repo](http://example.com) * Email us at [example email address](mailto:example@example.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/argoproj/argo-workflows/v3
Introduced in:
3.1.0Fixed in: 3.1.6Fix
go get github.com/argoproj/argo-workflows/v3@v3.1.6References
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-h563-xh25-x54q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-37914[ADVISORY]
- https://github.com/argoproj/argo-workflows/issues/6441[WEB]
- https://github.com/argoproj/argo-workflows/pull/6285[WEB]
- https://github.com/argoproj/argo-workflows/pull/6442[WEB]
- https://github.com/argoproj/argo-workflows/commit/2a2ecc916925642fd8cb1efd026588e6828f82e1[WEB]
- github.com/argoproj/argo-workflows/v3[PACKAGE]