REDHAT-BUG-2468446: High severity Argo Argo Workflows vulnerability
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Argo Workflowsto a version that resolves this vulnerability.Fixed in 3.7.14 - Upgrade
Upgrade
Argo Workflowsto a version that resolves this vulnerability.Fixed in 4.0.5
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2468446?
The severity of REDHAT-BUG-2468446 is classified as high with a score of 7.
What is the risk associated with REDHAT-BUG-2468446?
The risk associated with REDHAT-BUG-2468446 is rated at 33.
How do I fix REDHAT-BUG-2468446?
To fix REDHAT-BUG-2468446, upgrade to Argo Workflows version 3.7.14 or 4.0.5 or later.
What vulnerabilities does REDHAT-BUG-2468446 exploit?
REDHAT-BUG-2468446 exploits the ability of a user with create Workflow permissions to bypass templateReferencing: Strict.
Which version of Argo Workflows is affected by REDHAT-BUG-2468446?
Versions prior to 3.7.14 and 4.0.5 of Argo Workflows are affected by REDHAT-BUG-2468446.