Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/rancher/backup-restore-operator
  4. ›
  5. CVE-2025-62879

CVE-2025-62879: Rancher Backup Operator pod's logs leak S3 tokens

March 3, 2026 (updated March 4, 2026)

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod’s logs.

Specifically, the S3 accessKey and secretKey are exposed in the pod’s logs under the following logging level conditions:

Variable ExposedLogging Level Condition
accessKeytrace: false (default), and debug: false (default)
secretKeytrace: true or debug: true

Note: The S3 accessKey is exposed in the logs without requiring any supplementary configuration.

For further information on this attack category, please consult the associated MITRE ATT&CK - Technique - Log Enumeration.

References

  • bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62879
  • github.com/advisories/GHSA-wj3p-5h3x-c74q
  • github.com/rancher/backup-restore-operator
  • github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q
  • nvd.nist.gov/vuln/detail/CVE-2025-62879

Code Behaviors & Features

Detect and mitigate CVE-2025-62879 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 6.0.0 before 6.0.3, all versions starting from 7.0.0 before 7.0.5, all versions starting from 8.0.0 before 8.1.2, all versions starting from 9.0.0 before 9.0.1

Fixed versions

  • 9.0.1
  • 8.1.2
  • 7.0.5
  • 6.0.3

Solution

Upgrade to versions 6.0.3, 7.0.5, 8.1.2, 9.0.1 or above.

Impact 6.8 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-532: Insertion of Sensitive Information into Log File

Source file

go/github.com/rancher/backup-restore-operator/CVE-2025-62879.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:57 +0000.