CVE-2025-62879

Aliases:GHSA-wj3p-5h3x-c74qGO-2026-4591CGA-43m5-6j29-xh2xCGA-4g3w-2c33-8393CGA-7h7w-h5h3-gg32CGA-fcrq-36p9-5379CGA-fjjw-whq8-hcr4CGA-hq2v-vwpc-whfxCGA-j4v5-7mh3-mmfvCGA-m3w5-wg6j-8xw9CGA-pp3c-q6gf-9887CGA-prg7-37w2-cpxxCGA-pv6v-x989-9cr6CGA-qqc7-6x4w-vm2rCGA-r2c9-2884-9xfxCGA-rr6m-886h-g447CGA-rv48-89m7-6vfgCGA-xjf3-wxgj-w3q7
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 04 Mar 2026, 15:08
Last modified:04 Mar 2026, 16:11

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.34% LOW
0% probability +0.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Mar 2026, 15:08
Published
Vulnerability first disclosed
04 Mar 2026, 16:11
Last Modified
Vulnerability information updated

Description

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

CVSS Metrics

  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
  • v3.1MEDIUMScore: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.34% Percentile: 28%

Techniques & Countermeasures

  • CWE-532Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

Affected Systems

  • chainguardbackup-restore-operator-10.0

    < 0

  • chainguardbackup-restore-operator-7.0

    < 7.0.5-r0

  • chainguardbackup-restore-operator-8.1

    < 8.1.2-r0

  • chainguardbackup-restore-operator-9.0

    < 9.0.1-r0

  • chainguardbackup-restore-operator-fips-10.0

    < 0

  • chainguardbackup-restore-operator-fips-7.0

    < 7.0.5-r0

  • chainguardbackup-restore-operator-fips-8.1

    < 8.1.2-r0

  • chainguardbackup-restore-operator-fips-9.0

    < 9.0.1-r0

  • github.com/rancherbackup-restore-operator

    all | ≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.1.2 | ≥ 7.0.0, < 7.0.5 | ≥ 6.0.0, < 6.0.3

  • suserancher

    ≥ 9.0.0, < 9.0.1 | ≥ 8.0.0, < 8.1.2 | ≥ 7.0.0, < 7.0.5 | ≥ 6.0.0, < 6.0.3

  • suserancher_backup_and_restore_operator

    ≥ 6.0.0, < 6.0.3 | ≥ 7.0.0, < 7.0.5 | ≥ 8.0.0, < 8.1.2 | ≥ 9.0.0, < 9.0.1

References (6)