Database/Container, Kubernetes & orchestration
Argo Workflows (workflow-controller, artifact repository credential logging): Workflow-controller writes artifact
Impact
Workflow-controller writes artifact repository credentials into its own logs in plaintext. Anyone who can read pod logs in the Argo namespace - a monitoring sidecar, an on-call engineer, a tenant with over-broad RBAC - gets full read/write/delete on the shared artifact bucket that holds every tenant's inputs, checkpoints and outputs.
Who can reach it
A principal with get on pods/log for the workflow-controller pod, or read access to whatever log pipeline collects it.
What to do
Upgrade to 3.6.12 or 3.7.3 and restart the controller, then rotate the artifact repository credentials. Note the sibling CVE-2026-42295 covers the same leak in the executor, so patch both before declaring the credentials clean.
References
Related entries
- KubeVirt: hostDisk feature mounts host files into a VM with insufficient restrictionCVE-2025-64324 · KubeVirtHigh
- Contrast initializer: regression re-exposes workload secrets by logging the full NewMeshCert responseCVE-2025-71423 · Contrast initializer (NewMeshCert response logged at INFO, versions 1.9.0-1.12.2)High
- Contrast initializer: workload secrets logged to Kubernetes pod logs at the default log levelCVE-2025-71425 · Contrast initializer (workload secret written to stderr at default log level)High
- LXD: crafted image templates escape the instance template directory and read or create host filesCVE-2026-16033 · LXD (image metadata template handling, QEMU/VM driver paths)High
- RHACM cluster-proxy: caller-supplied impersonation headers grant cluster-admin on managed clustersCVE-2026-17107 · Red Hat ACM / multicluster-engine cluster-proxy (service-proxy impersonation headers)High
- Argo Workflows (workflow executor, artifact driver logging): The executor logs the whole artifact driver struct, so S3CVE-2026-42295 · Argo Workflows (workflow executor, artifact driver logging)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.