216.73.217.22

CVE-2024-52814

· Published 22/11/2024 16:15 · Modified 22/11/2024 16:15

Labels: CVE-2024-52814 2024-11-22CVE-2024-52814CWE-1220[email protected]

Essential information

Published
22/11/2024 16:15
Modified
22/11/2024 16:15
Author
Creator
CVSS
2.8 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CVSS metrics

Description

Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only certain types of Pods created by the Controller require these privileges. The impact is minimal, as an attack could only affect status reporting for certain types of Pods and templates. Version 0.45.0 fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References