Junglewise Threat Intelligence

GO-2022-0405 - Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workf

Severity: info · Published 2024-08-21

Technologies: github.com/argoproj/argo-workflows/v3 (Go), github.com/argoproj/argo-workflows/v2 (Go), github.com/argoproj/argo-workflows (Go). Vendors: Go.

Executive brief

Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` in github.com/argoproj/argo-workflows

Affected products

  • Go github.com/argoproj/argo-workflows/v3
  • Go github.com/argoproj/argo-workflows/v2
  • Go github.com/argoproj/argo-workflows

Related threats