CVE-2021-37914
EUVD-2021-173803.08.2021, 00:15
In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| argoproj | argo_workflows | 𝑥 ≤ 3.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration