Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42183

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level RBAC rule but not an SSO-namespace rule, when SSO_DELEGATE_RBAC_TO_NAMESPACE=true. This issue has been patched in version 4.0.5.

A flaw was found in Argo Workflows. This flaw, a nil pointer dereference in the rbacAuthorization() function, affects Single Sign-On (SSO) users. When SSO_DELEGATE_RBAC_TO_NAMESPACE is enabled, an authenticated SSO user whose claims match a namespace-level Role-Based Access Control (RBAC) rule but not an SSO-namespace rule can trigger a system panic. This can lead to a Denial of Service (DoS) for the affected system.

Меры по смягчению последствий

To mitigate this issue, disable the SSO_DELEGATE_RBAC_TO_NAMESPACE feature if it is not required for your deployment. This will prevent the vulnerable code path from being exercised. Disabling this feature may affect how RBAC is delegated to namespaces for SSO users. A restart of the Argo Workflows service may be required for the change to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-argoexec-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-argoexec-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2468445github.com/argoproj/argo-workflows: Argo Workflows: Denial of Service via nil pointer dereference for SSO users

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level RBAC rule but not an SSO-namespace rule, when SSO_DELEGATE_RBAC_TO_NAMESPACE=true. This issue has been patched in version 4.0.5.

github
3 месяца назад

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

5.3 Medium

CVSS3