REDHAT-BUG-2431881: XSS
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under the Argo Server origin, enabling API actions with the victim’s privileges. Versions 3.6.17 and 3.7.8 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
argo-workflowsto a version that resolves this vulnerability.Fixed in 3.6.17 - Upgrade
Upgrade
argo-workflowsto a version that resolves this vulnerability.Fixed in 3.7.8
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2431881?
The severity of REDHAT-BUG-2431881 is rated high with a score of 7.
How do I fix REDHAT-BUG-2431881?
To fix REDHAT-BUG-2431881, upgrade to versions 3.6.17 or 3.7.8 or later of Argo Workflows.
What type of vulnerability is REDHAT-BUG-2431881?
REDHAT-BUG-2431881 is a stored Cross-Site Scripting (XSS) vulnerability.
What component of Argo Workflows is affected by REDHAT-BUG-2431881?
REDHAT-BUG-2431881 affects the artifact directory listing feature of Argo Workflows.
Who is at risk from REDHAT-BUG-2431881?
Workflow authors using affected versions of Argo Workflows are at risk from REDHAT-BUG-2431881.