Database/Container, Kubernetes & orchestration
Argo Workflows (workflow executor, artifact driver logging): The executor logs the whole artifact driver struct, so S3
Impact
The executor logs the whole artifact driver struct, so S3 access keys, GCS service account keys, Azure account keys and Git passwords land in plaintext workflow pod logs. Any tenant with pod-log read in that namespace walks off with the artifact repository credentials and can read, overwrite or delete every other tenant's datasets and model artifacts. Incomplete fix of CVE-2025-62157, which covered the controller but not the executor.
Who can reach it
A user or service account with get/list on pods/log in a namespace where workflows run. No workflow submission rights needed.
What to do
Upgrade to 4.0.5 and restart controller and server so new executors ship the fixed logging. Then rotate the artifact repository credentials and tighten pods/log RBAC - the credentials are already in whatever log store scraped those pods.
References
Related entries
- Argo Workflows (Argo Server, ConfigMap-backed sync limit provider): The Sync Service's ConfigMap provider runs noCVE-2026-42297 · Argo Workflows (Argo Server, ConfigMap-backed sync limit provider)High
- KubeVela: a ComponentDefinition can point terraform.path at a symlink and OOM-kill the cluster-wide controllerCVE-2026-55108 · KubeVela vela-core controller (Terraform remote configuration loader, GetTerraformConfigurationFromRemote)High
- CloudNativePG: managed-role passwords exposed via pg_stat_statements, enabling command execution in the DB podCVE-2026-55765 · CloudNativePG operator (managed-role password handling)High
- Kamaji: colliding tenant name normalization lets one tenant read or destroy another's control-plane stateCVE-2026-62246 · Kamaji hosted control plane manager (TenantControlPlane datastore schema/user derivation)High
- Docker / moby: Command execution via crafted remote git build path in `docker build`CVE-2019-13139 · Docker / mobyHigh
- Rancher: Sensitive data leaked into Rancher audit logsCVE-2023-22649 · RancherHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.