Improper access control in Argo Workflows - CVE-2022-29164

 

Improper access control in Argo Workflows - CVE-2022-29164

Published: May 4, 2022 / Updated: April 23, 2026


Vulnerability identifier: #VU126899
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29164
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read information about the victim's workflows and create or delete workflows.

The vulnerability exists due to improper access control in HTML artifact handling when rendering a crafted HTML artifact that issues XHR requests to the Argo Server API. A remote user can send a deep-link to a crafted artifact to cause the victim's browser to interact with the API using the victim's privileges.

User interaction is required, and exploitation requires the ability to run workflows in the same cluster as the victim.


Affected software

Argo Workflows

How to mitigate CVE-2022-29164

Install security update from vendor's website.

Argo Workflows - addressed in versions 3.2.11, 3.3.5

External References

Related Security Bulletins