argo-workflows@6.3.0rc5 vulnerabilities

Argo Workflows API

Direct Vulnerabilities

Known vulnerabilities in the argo-workflows package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

argo-workflows is an Argo Workflows API

Affected versions of this package are vulnerable to Directory Traversal by allowing unauthenticated users to pass parameters that are templated into input artifact destination paths.

How to fix Directory Traversal?

Upgrade argo-workflows to version 6.3.0rc9 or higher.

[,6.3.0rc9)