—
GO-2024-3226
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows
Quick fix
GO-2024-3226 — github.com/argoproj/argo-workflows/v3: upgrade to the fixed version with the command below.
go get github.com/argoproj/argo-workflows/v3@v3.6.0-rc2Details
Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/argoproj/argo-workflows
Introduced in:
0No fixed version published yet for github.com/argoproj/argo-workflows (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/argoproj/argo-workflows/v2
Introduced in:
0No fixed version published yet for github.com/argoproj/argo-workflows/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/argoproj/argo-workflows/v3
Introduced in:
3.6.0-rc1Fixed in: 3.6.0-rc2Fix
go get github.com/argoproj/argo-workflows/v3@v3.6.0-rc2References
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-ghjw-32xw-ffwr[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-47827[ADVISORY]
- https://github.com/argoproj/argo-workflows/commit/524406451f4dfa57bf3371fb85becdb56a2b309a[FIX]
- https://github.com/argoproj/argo-workflows/pull/13641[FIX]
- https://github.com/argoproj/argo-workflows/blob/ce7f9bfb9b45f009b3e85fabe5e6410de23c7c5f/workflow/metrics/metrics_k8s_request.go#L75[WEB]