Vulnerabilities > CVE-2024-47827 - Excessive Reliance on Global Variables vulnerability in Argo Workflows Project Argo Workflows 3.6.0

047910
CVSS 4.8 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in 3.6.0-rc2.

Vulnerable Configurations

Part Description Count
Application
Argo_Workflows_Project
1

Common Weakness Enumeration (CWE)