Medium severity6.8NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2025-62879
CVE-2025-62879
Description
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/backup-restore-operatorGo | >= 9.0.0, < 9.0.1 | 9.0.1 |
github.com/rancher/backup-restore-operatorGo | >= 8.0.0, < 8.1.2 | 8.1.2 |
github.com/rancher/backup-restore-operatorGo | >= 7.0.0, < 7.0.5 | 7.0.5 |
github.com/rancher/backup-restore-operatorGo | >= 6.0.0, < 6.0.3 | 6.0.3 |
Affected products
10- cpe:2.3:a:suse:rancher_backup_and_restore_operator:*:*:*:*:*:*:*:*Range: >=6.0.0,<6.0.3
- osv-coords8 versionspkg:apk/chainguard/backup-restore-operator-10.0pkg:apk/chainguard/backup-restore-operator-7.0pkg:apk/chainguard/backup-restore-operator-8.1pkg:apk/chainguard/backup-restore-operator-fips-10.0pkg:apk/chainguard/backup-restore-operator-fips-8.1pkg:golang/github.com/rancher/backup-restore-operatorpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: < 7.0.5-r0
- (no CPE)range: < 8.1.2-r0
- (no CPE)range: < 0
- (no CPE)range: < 8.1.2-r0
- (no CPE)range: >= 9.0.0, < 9.0.1
- (no CPE)range: < 0.0.20260317T205859-150000.1.152.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
4- bugzilla.suse.com/show_bug.cginvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-wj3p-5h3x-c74qnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-62879ghsaADVISORY
- github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74qghsaWEB
News mentions
0No linked articles in our index yet.