Database/Container, Kubernetes & orchestration
Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod): In this configuration the client's
Impact
In this configuration the client's supplied key is ignored and the server's own Kubernetes credentials are used instead. Every request silently runs at the server's privilege level, so a tenant with a narrow client identity gets whatever the Argo Server account can do across the cluster.
Who can reach it
Any client authenticating to an Argo Server that runs outside a Kubernetes pod (bare metal or VM) with --auth-mode=client on Kubernetes 1.19 or newer, where the server account is more privileged than the client.
What to do
Upgrade to 3.0.9 or 3.1.6 and restart. There is no workaround for the affected versions - if you cannot upgrade, run Argo Server inside the cluster as a pod and scope its service account down to the minimum.
References
Related entries
- Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod): In this configuration the client'sNCVD-2021-019-argo-workflows-argo-server-auth · Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod)Unscored
- Argo Workflows (Argo Server default --auth-mode=server before 3.0): Before 3.0 the Argo Server defaulted toNCVD-2021-015-argo-workflows-argo-server-defau · Argo Workflows (Argo Server default --auth-mode=server before 3.0)Unscored
- Argo Workflows (Argo Server, TLS keys baked into the container image): Argo Server's TLS private keys ship inside theNCVD-2021-018-argo-workflows-argo-server-tls-k · Argo Workflows (Argo Server, TLS keys baked into the container image)Unscored
- Argo Workflows (Argo Server default --auth-mode=server before 3.0): Before 3.0 the Argo Server defaulted toNCVD-2021-020-argo-workflows-argo-server-defau · Argo Workflows (Argo Server default --auth-mode=server before 3.0)Unscored
- Argo CD: Unauthenticated attacker forges JWTs and gains full Argo CD admin, which in a GitOps clusterCVE-2022-29165 · Argo CDCritical
- Envoy: OAuth filter does not validate access tokens, so authentication can be skipped entirelyCVE-2022-29226 · EnvoyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.