SB2022050458 - Improper access control in Argo Workflows



SB2022050458 - Improper access control in Argo Workflows

Published: May 4, 2022 Updated: April 23, 2026

Security Bulletin ID SB2022050458
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2022-29164)

The vulnerability allows a remote user to read information about the victim's workflows and create or delete workflows.

The vulnerability exists due to improper access control in HTML artifact handling when rendering a crafted HTML artifact that issues XHR requests to the Argo Server API. A remote user can send a deep-link to a crafted artifact to cause the victim's browser to interact with the API using the victim's privileges.

User interaction is required, and exploitation requires the ability to run workflows in the same cluster as the victim.


Remediation

Install update from vendor's website.