Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This exists in all versions up to 2.4.1 and is fixed in 2.4.2. This vulnerability is specific to the Ruby on Rails Workbench application (“Workbench 1”). We do not believe any other Arvados components, including the TypesScript browser-based Workbench application (“Workbench 2”) or API Server, are vulnerable to this attack. For versions of Arvados earlier than 2.4.2: remove the Ruby-based "Workbench 1" app ("apt-get remove arvados-workbench") from your installation as a workaround.
History

Wed, 23 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-08-14T00:20:10.000Z

Updated: 2025-04-23T17:50:28.144Z

Reserved: 2022-07-15T00:00:00.000Z

Link: CVE-2022-36006

cve-icon Vulnrichment

Updated: 2024-08-03T09:51:59.803Z

cve-icon NVD

Status : Modified

Published: 2022-08-15T11:21:40.330

Modified: 2024-11-21T07:12:10.030

Link: CVE-2022-36006

cve-icon Redhat

No data.