Missing Authorization in Argo Workflows - CVE-2024-53862

 

Missing Authorization in Argo Workflows - CVE-2024-53862

Published: December 2, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU126898
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53862
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive workflow information.

The vulnerability exists due to missing authorization in the GET Workflow endpoint fallback to archived workflows when handling requests to retrieve archived workflows in client or sso mode. A remote attacker can send a request with a spoofed or otherwise unauthorized token to disclose sensitive workflow information.

Only deployments with workflow archiving enabled are affected.


Affected software

Argo Workflows

How to mitigate CVE-2024-53862

Install security update from vendor's website.

Argo Workflows - addressed in versions 3.5.13, 3.6.2

External References

Related Security Bulletins