Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47827

Опубликовано: 28 окт. 2024
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in 3.6.0-rc2.

A flaw was found in Argo Workflows. Due to a race condition in a global variable, the Argo Workflows controller can crash on command by any user with access to execute a workflow, which can lead to a denial of service.

Отчет

This flaw was introduced in version 3.6.0-rc1 and patched in the subsequent 3.6.0-rc2 release. The vulnerable version of Argo Workflows is not shipped in any Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)odh-data-science-pipelines-argo-argoexec-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-data-science-pipelines-argo-workflowcontroller-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-api-server-v2-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-driver-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-launcher-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-persistenceagent-v2-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-scheduledworkflow-v2-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1108
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2322162argo-workflows: Argo Workflows Controller: Denial of Service via malicious daemon Workflows

EPSS

Процентиль: 42%
0.00199
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
около 1 года назад

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in 3.6.0-rc2.

CVSS3: 5.7
github
около 1 года назад

Argo Workflows Controller: Denial of Service via malicious daemon Workflows

suse-cvrf
около 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 42%
0.00199
Низкий

4.8 Medium

CVSS3