Логотип exploitDog
bind:CVE-2026-28229
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-28229

Количество 3

Количество 3

redhat логотип

CVE-2026-28229

16 дней назад

A flaw was found in Argo Workflows in which an attacker can leak sensitive information contained in Workflow Templates and Cluster Workflow Templates. Because the functions that retrieve template information use server permissions, no authorization is required to read templates which might contain secrets such as passwords, API keys, or other sensitive data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-28229

16 дней назад

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-56px-hm34-xqj5

16 дней назад

Unauthorized access to Argo Workflows Template

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-28229

A flaw was found in Argo Workflows in which an attacker can leak sensitive information contained in Workflow Templates and Cluster Workflow Templates. Because the functions that retrieve template information use server permissions, no authorization is required to read templates which might contain secrets such as passwords, API keys, or other sensitive data.

CVSS3: 7.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-28229

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak sensitive template content, including embedded Secret manifests. This vulnerability is fixed in 4.0.2 and 3.7.11.

CVSS3: 9.8
0%
Низкий
16 дней назад
github логотип
GHSA-56px-hm34-xqj5

Unauthorized access to Argo Workflows Template

CVSS3: 7.5
0%
Низкий
16 дней назад

Уязвимостей на страницу