CVE-2025-62157

EPSS 0.01%

Argo Workflows exposes artifact repository credentials in workflow-controller logs

發布日:2025/10/14修改日:2025/11/5
也稱為:GHSA-c2hv-4pfj-mm2rBIT-argo-workflows-2025-62157CGA-m28m-rc6w-52qpGO-2025-4024

描述

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

參考連結(6)