CVE-2025-62879
Aliases:GHSA-wj3p-5h3x-c74qGO-2026-4591CGA-43m5-6j29-xh2xCGA-4g3w-2c33-8393CGA-7h7w-h5h3-gg32CGA-fcrq-36p9-5379CGA-fjjw-whq8-hcr4CGA-hq2v-vwpc-whfxCGA-j4v5-7mh3-mmfvCGA-m3w5-wg6j-8xw9CGA-pp3c-q6gf-9887CGA-prg7-37w2-cpxxCGA-pv6v-x989-9cr6CGA-qqc7-6x4w-vm2rCGA-r2c9-2884-9xfxCGA-rr6m-886h-g447CGA-rv48-89m7-6vfgCGA-xjf3-wxgj-w3q7
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Analyzed
Published: 04 Mar 2026, 15:08
Last modified:04 Mar 2026, 16:11
Vulnerability Summary
Overall Risk (default)
medium
27/100 CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.34% LOW
0% probability +0.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Mar 2026, 15:08
Published
Vulnerability first disclosed
04 Mar 2026, 16:11
Last Modified
Vulnerability information updated
Description
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- v3.1•MEDIUM•Score: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.34%• Percentile: 28%
Techniques & Countermeasures
- CWE-532•Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
Affected Systems
- chainguard•backup-restore-operator-10.0
< 0
- chainguard•backup-restore-operator-7.0
< 7.0.5-r0
- chainguard•backup-restore-operator-8.1
< 8.1.2-r0
- chainguard•backup-restore-operator-9.0
< 9.0.1-r0
- chainguard•backup-restore-operator-fips-10.0
< 0
- chainguard•backup-restore-operator-fips-7.0
< 7.0.5-r0
- chainguard•backup-restore-operator-fips-8.1
< 8.1.2-r0
- chainguard•backup-restore-operator-fips-9.0
< 9.0.1-r0
- github.com/rancher•backup-restore-operator
all | ≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.1.2 | ≥ 7.0.0, < 7.0.5 | ≥ 6.0.0, < 6.0.3
- suse•rancher
≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.1.2 | ≥ 7.0.0, < 7.0.5 | ≥ 6.0.0, < 6.0.3
- suse•rancher_backup_and_restore_operator
≥ 6.0.0, < 6.0.3 | ≥ 7.0.0, < 7.0.5 | ≥ 8.0.0, < 8.1.2 | ≥ 9.0.0, < 9.0.1
References (6)
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62879
- https://github.com/advisories/GHSA-wj3p-5h3x-c74q
- https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q
- https://nvd.nist.gov/vuln/detail/CVE-2025-62879
- https://github.com/rancher/backup-restore-operator
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62879.json