Skip to content

Attack on Kubernetes via Misconfigured Argo Workflows

Moderate
alexec published GHSA-rc7p-gmvh-xfx2 Jul 22, 2021

Package

No package listed

Affected versions

<v3.0.0

Patched versions

v3.0.0

Description

Impact

Users running using the Argo Server with --auth-mode=server (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining.

Resolution

  • Do not expose your user interface to the Internet.
  • Change configuration. --auth-mode=client.

References

https://www.intezer.com/blog/container-security/new-attacks-on-kubernetes-via-misconfigured-argo-workflows/

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs