CVE-2021-37914
03.08.2021, 00:15
In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.Enginsight
Vendor | Product | Version |
---|---|---|
argo-workflows_project | argo-workflows | 𝑥 ≤ 3.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration