UNKNOWN Go
Workflow re-write vulnerability using input parameter
GHSA-h563-xh25-x54q · BIT-argo-workflows-2021-37914 · CVE-2021-37914 · GO-2022-0928
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
- Allow end-users to set input parameters, but otherwise expect workflows to be secure.
Patches
Not yet.
Workarounds
- Set
EXPRESSION_TEMPLATES=falsefor the workflow controller
References
For more information
If you have any questions or comments about this advisory:
- Open an issue in example link to repo
- Email us at example email address
References
- WEB https://github.com/argoproj/argo-workflows/security/advisories/GHSA-h563-xh25-x54q
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-37914
- WEB https://github.com/argoproj/argo-workflows/issues/6441
- WEB https://github.com/argoproj/argo-workflows/pull/6285
- WEB https://github.com/argoproj/argo-workflows/pull/6442
- WEB https://github.com/argoproj/argo-workflows/commit/2a2ecc916925642fd8cb1efd026588e6828f82e1
- PACKAGE github.com/argoproj/argo-workflows/v3
Ready to move
Start Securing
Free, no credit card | First findings in minutes