Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28229

Опубликовано: 11 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

A flaw was found in Argo Workflows in which an attacker can leak sensitive information contained in Workflow Templates and Cluster Workflow Templates. Because the functions that retrieve template information use server permissions, no authorization is required to read templates which might contain secrets such as passwords, API keys, or other sensitive data.

Отчет

An Important flaw was found in Argo Workflows, as used in Red Hat OpenShift AI. This vulnerability allows an attacker to gain unauthorized access to Workflow Templates and Cluster Workflow Templates due to insufficient authorization checks. This could lead to the disclosure of sensitive information, including embedded secrets like passwords and API keys.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-argoexec-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8Not affected
Red Hat OpenShift AI 2.25rhoai/odh-data-science-pipelines-argo-argoexec-rhel9FixedRHSA-2026:1018423.04.2026
Red Hat OpenShift AI 2.25rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9FixedRHSA-2026:1018423.04.2026
Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-api-server-v2-rhel9FixedRHSA-2026:1018423.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2446549argo-workflows: Argo Workflows has unauthorized access to Argo Workflows Template

EPSS

Процентиль: 47%
0.00652
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

CVSS3: 7.5
github
5 месяцев назад

Unauthorized access to Argo Workflows Template

EPSS

Процентиль: 47%
0.00652
Низкий

7.5 High

CVSS3