argo-workflows@3.1.1 vulnerabilities

Argo Workflows API

Direct Vulnerabilities

Known vulnerabilities in the argo-workflows package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Directory Traversal in the lint.go component, by not sanitizing the path argument given to the os.Open() function.

How to fix Directory Traversal?

Upgrade argo-workflows to version 6.3.0rc2 or higher.

[,6.3.0rc2)
  • H
Directory Traversal

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Directory Traversal by allowing unauthenticated users to pass parameters that are templated into input artifact destination paths.

How to fix Directory Traversal?

Upgrade argo-workflows to version 6.3.0rc9 or higher.

[,6.3.0rc9)
  • M
Cross-site Scripting (XSS)

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the sso.go component.

How to fix Cross-site Scripting (XSS)?

Upgrade argo-workflows to version 5.0.0 or higher.

[,5.0.0)
  • M
Information Exposure

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Information Exposure by displaying the current cookie in the login page, and not setting up the Secure flag.

How to fix Information Exposure?

Upgrade argo-workflows to version 5.0.0 or higher.

[,5.0.0)
  • H
Cryptographic Issues

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Cryptographic Issues by using versions of TLS protocols lower than 1.2.

How to fix Cryptographic Issues?

Upgrade argo-workflows to version 6.3.0rc2 or higher.

[,6.3.0rc2)
  • M
Information Exposure

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Information Exposure by allowing to list archived workflows that shouldn't be accessible.

How to fix Information Exposure?

Upgrade argo-workflows to version 5.0.0 or higher.

[,5.0.0)