Argo Workflows 4.1.0 至 4.1.3 版本中的 函数存在一个授权绕过漏洞:当元数据的 字段选择器使用“不等于”(NotEquals)运算符时,未应用集群范围的访问审查。拥有命名空间范围 list 权限的攻击者可以利用取反的命名空间字段选择器,检索所有其他命名空间中的已归档工作流,从而暴露工作流的 spec 参数、参数值以及注释(annotations)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| argoproj | argo-workflows | 4.1.0 ~ 4.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet