OSV 1.4.0 · github-reviewed · 修改于 2021-08-24 01:02
发布时间
2021-08-24 03:41
GitHub 审查时间
2021-08-24 01:02
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/08/GHSA-6c73-2v8x-qpvm/GHSA-6c73-2v8x-qpvm.json
We are not aware of any exploits. This is a pro-active fix.
Impacted:
--secure=true or >= v3.0 with --secure unspecified (note - running in secure mode is recommended regardless).The Argo Server's keys are packaged within the image. They could be extracted and used to decrypt traffic, or forge requests.
https://github.com/argoproj/argo-workflows/pull/6540
This was identified by engineers at Jetstack.io