GPU VulnDB

Database/Container, Kubernetes & orchestration

Argo Workflows Helm chart (argo-helm, workflow-role privileges on workflowtasksets / workflowartifactgctasks): The

CVE-2024-52814Container, Kubernetes & orchestrationGHSA-h974-w8pg-cx73curated

Impact

The chart hands workflowtasksets and workflowartifactgctasks permissions to every workflow pod when only agent and artifact-GC pods need them. A tenant workload can tamper with status reporting for other pods and templates. Impact is limited to status integrity, not code execution.

Who can reach it

A user who can get a workflow executed in the namespace, on argo-helm charts below 0.45.0.

What to do

Upgrade the argo-workflows Helm chart to 0.45.0 or later and apply. Roll it together with the 0.44.0 fix for CVE-2024-52799 - both are edits to the same workflow-role and land without a controller restart.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.