pkg:Bitnami/argo-workflows
共 16 筆 CVEHIGH6MEDIUM2
✅ 檢查你的版本
所有已知漏洞
- HIGH8.1CVE-2026-42296Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Securefrom 0, < 3.7.14, >= 4.0.0, < 4.0.5
- HIGH8.1CVE-2025-66626RCE via ZipSlip and symbolic links in argoproj/argo-workflows in github.com/argoproj/argo-workflowsfrom 0, < 2.5.3, >= 3.0.0, < 3.6.14
- from 0, < 3.6.12, >= 3.7.0, < 3.7.3
- HIGH7.7CVE-2026-40886Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller>= 3.6.5, < 3.7.14, >= 4.0.0, < 4.0.5
- from 0, < 3.7.11, >= 4.0.0, < 4.0.2
- >= 2.6.0, < 3.2.11, >= 3.3.0, < 3.3.5
- MEDIUM6.5CVE-2021-37914Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflowsfrom 0, < 3.1.4
- MEDIUM5.7CVE-2024-47827Argo Workflows Controller: Denial of Service via malicious daemon Workflows in github.com/argoproj/argo-workflows>= 3.6.0-rc1, < 3.6.0-rc2
- >= 4.0.0, < 4.0.5
- from 0, < 3.7.14, >= 4.0.0, < 4.0.5
- >= 4.0.0, < 4.0.5
- >= 4.0.0, < 4.0.5
- >= 2.9.0, < 3.7.11, >= 4.0.0, < 4.0.2
- —CVE-2026-23960Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflowsfrom 0, < 3.6.17, >= 3.7.0, < 3.7.8
- —CVE-2025-62157Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflowsfrom 0, < 3.6.12, >= 3.7.0, < 3.7.3
- >= 3.5.7, < 3.6.2