Database/Container, Kubernetes & orchestration
Argo Workflows (Argo Server, HTML artifact serving): A workflow can emit an HTML artifact containing script that, when
Impact
A workflow can emit an HTML artifact containing script that, when a victim opens the artifact deep link, runs on the Argo Server origin and drives the API through XHR with the victim's session. A low-privilege tenant escalates to whatever an admin who clicks the link can do - create workflows, read templates and secrets, delete other tenants' work.
Who can reach it
A tenant with workflow-submit rights produces the artifact and gets a higher-privileged user to open its link, typically by email.
What to do
Upgrade Argo Server to 3.2.11 or 3.3.5 and restart. Serve artifacts from a separate origin or object-store domain rather than the Argo Server domain wherever possible, so a malicious artifact cannot borrow the UI's session.
References
Related entries
- Podman: Incorrect supplementary group handlingCVE-2022-2989 · PodmanHigh
- CRI-O: Incorrect supplementary group handling leads to information disclosure between workloadsCVE-2022-2995 · CRI-OHigh
- cosign / sigstore: `cosign verify-attestation --type` returns a false positive if any attestation existsCVE-2022-35929 · cosign / sigstoreHigh
- Rancher: Insufficient entropy means a leaked cattle-token stays usable after rotationCVE-2022-43755 · RancherHigh
- Envoy: embedded null byte in an OTHERNAME SAN can satisfy match_typed_subject_alt_namesCVE-2025-66220 · Envoy mTLS certificate matcher (match_typed_subject_alt_names, OTHERNAME SAN)High
- Contrast Coordinator: recovery accepts an unverified seed, enabling a rogue Coordinator to impersonate the real oneCVE-2025-71426 · Contrast (edgelesssys/contrast) Coordinator recovery (unauthenticated seed)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.