CVE-2025-62157

Source
https://cve.org/CVERecord?id=CVE-2025-62157
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62157.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62157
Aliases
Downstream
Related
Published
2025-10-14T15:06:39.829Z
Modified
2026-04-02T12:57:46.210610Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Argo Workflows exposes artifact repository credentials in workflow-controller logs
Details

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.

Database specific
{
    "cwe_ids": [
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62157.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/argoproj/argo-workflows

Affected ranges

Type
GIT
Repo
https://github.com/argoproj/argo-workflows
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.7.0"
        },
        {
            "fixed": "3.7.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/argoproj/argo-workflows
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.6.12"
        }
    ]
}

Affected versions

Other
ls
stable
ui-v3-rc1
v0.*
v0.0.0-dev-bom-1
v0.0.0-dev-bom-2
v0.0.0-dev-build-1
v0.0.0-dev-build-2
v0.0.0-dev-build-3
v0.0.0-dev-build-4
v0.0.0-dev-dataflow-1
v0.0.0-dev-dataflow-10
v0.0.0-dev-dataflow-11
v0.0.0-dev-dataflow-13
v0.0.0-dev-dataflow-14
v0.0.0-dev-dataflow-15
v0.0.0-dev-dataflow-16
v0.0.0-dev-dataflow-17
v0.0.0-dev-dataflow-18
v0.0.0-dev-dataflow-19
v0.0.0-dev-dataflow-2
v0.0.0-dev-dataflow-20
v0.0.0-dev-dataflow-21
v0.0.0-dev-dataflow-22
v0.0.0-dev-dataflow-23
v0.0.0-dev-dataflow-24
v0.0.0-dev-dataflow-25
v0.0.0-dev-dataflow-26
v0.0.0-dev-dataflow-27
v0.0.0-dev-dataflow-28
v0.0.0-dev-dataflow-29
v0.0.0-dev-dataflow-3
v0.0.0-dev-dataflow-30
v0.0.0-dev-dataflow-31
v0.0.0-dev-dataflow-32
v0.0.0-dev-dataflow-33
v0.0.0-dev-dataflow-34
v0.0.0-dev-dataflow-35
v0.0.0-dev-dataflow-36
v0.0.0-dev-dataflow-37
v0.0.0-dev-dataflow-38
v0.0.0-dev-dataflow-39
v0.0.0-dev-dataflow-4
v0.0.0-dev-dataflow-40
v0.0.0-dev-dataflow-41
v0.0.0-dev-dataflow-42
v0.0.0-dev-dataflow-5
v0.0.0-dev-dataflow-6
v0.0.0-dev-dataflow-7
v0.0.0-dev-dataflow-8
v0.0.0-dev-dataflow-9
v0.0.0-dev-docker-0
v0.0.0-dev-kc-0
v0.0.0-dev-kc-1
v0.0.0-dev-kc-2
v0.0.0-dev-kc-3
v0.0.0-dev-kc-4
v0.0.0-dev-kc-5
v0.0.0-dev-kc-6
v0.0.0-dev-kc-7
v0.0.0-dev-mc-0
v0.0.0-dev-mc-1
v0.0.0-dev-mc-2
v0.0.0-dev-mc-3
v0.0.0-dev-mc-4
v0.0.0-dev-mc-5
v0.0.0-dev-mc-6
v0.0.0-dev-mc-7
v0.0.0-dev-mc-8
v0.0.0-dev-mc-9
v0.0.0-dev-pprof-1
v2.*
v2.0.0
v2.0.0-alpha1
v2.0.0-alpha2
v2.0.0-alpha3
v2.0.0-beta1
v2.1.0
v2.1.0-alpha1
v2.1.0-beta1
v2.1.0-beta2
v2.1.1
v2.1.2
v2.10.0
v2.10.0-rc1
v2.10.0-rc2
v2.10.0-rc3
v2.10.0-rc4
v2.10.0-rc5
v2.10.0-rc6
v2.10.0-rc7
v2.10.1
v2.10.2
v2.11.0
v2.11.0-rc1
v2.11.0-rc2
v2.11.0-rc3
v2.11.1
v2.11.2
v2.11.3
v2.11.4
v2.11.5
v2.11.6
v2.11.7
v2.11.8
v2.12.0
v2.12.0-rc1
v2.12.0-rc2
v2.12.0-rc3
v2.12.0-rc4
v2.12.0-rc5
v2.12.0-rc6
v2.12.1
v2.12.10
v2.12.11
v2.12.12
v2.12.13
v2.12.2
v2.12.3
v2.12.4
v2.12.5
v2.12.6
v2.12.7
v2.12.8
v2.12.9
v2.2.0
v2.2.1
v2.3.0
v2.3.0-rc1
v2.3.0-rc2
v2.3.0-rc3
v2.4.0
v2.4.0-rc1
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.0-rc1
v2.5.0-rc10
v2.5.0-rc11
v2.5.0-rc12
v2.5.0-rc2
v2.5.0-rc3
v2.5.0-rc4
v2.5.0-rc5
v2.5.0-rc6
v2.5.0-rc7
v2.5.0-rc8
v2.5.0-rc9
v2.5.1
v2.5.2
v2.5.3-rc4
v2.6.0
v2.6.0-rc1
v2.6.0-rc2
v2.6.0-rc3
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.0-rc1
v2.7.0-rc2
v2.7.0-rc3
v2.7.0-rc4
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.7.7
v2.8.0
v2.8.0-rc1
v2.8.0-rc2
v2.8.0-rc3
v2.8.0-rc4
v2.8.1
v2.8.2
v2.9.0
v2.9.0-rc1
v2.9.0-rc2
v2.9.0-rc3
v2.9.0-rc4
v2.9.1
v2.9.2
v2.9.3
v2.9.4
v2.9.5
v3.*
v3.0.0
v3.0.0-rc1
v3.0.0-rc2
v3.0.0-rc3
v3.0.0-rc4
v3.0.0-rc5
v3.0.0-rc6
v3.0.0-rc7
v3.0.0-rc8
v3.0.0-rc9
v3.0.1
v3.0.10
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.0-rc1
v3.1.0-rc10
v3.1.0-rc11
v3.1.0-rc12
v3.1.0-rc13
v3.1.0-rc14
v3.1.0-rc2
v3.1.0-rc3
v3.1.0-rc4
v3.1.0-rc5
v3.1.0-rc6
v3.1.0-rc7
v3.1.0-rc8
v3.1.0-rc9
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.14
v3.1.15
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.2.0-rc4
v3.2.0-rc5
v3.2.0-rc6
v3.2.1
v3.2.10
v3.2.11
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v3.3.0
v3.3.0-rc1
v3.3.0-rc10
v3.3.0-rc2
v3.3.0-rc3
v3.3.0-rc4
v3.3.0-rc5
v3.3.0-rc6
v3.3.0-rc7
v3.3.0-rc8
v3.3.0-rc9
v3.3.1
v3.3.10
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.3.8
v3.3.9
v3.4.0
v3.4.0-rc1
v3.4.0-rc2
v3.4.0-rc3
v3.4.0-rc4
v3.4.1
v3.4.10
v3.4.11
v3.4.12
v3.4.13
v3.4.14
v3.4.15
v3.4.16
v3.4.17
v3.4.18
v3.4.2
v3.4.3
v3.4.4
v3.4.5
v3.4.6
v3.4.7
v3.4.8
v3.4.9
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.1
v3.5.10
v3.5.11
v3.5.12
v3.5.13
v3.5.14
v3.5.15
v3.5.2
v3.5.3
v3.5.4
v3.5.5
v3.5.6
v3.5.7
v3.5.8
v3.5.9
v3.6.0
v3.6.0-rc1
v3.6.0-rc2
v3.6.0-rc3
v3.6.0-rc4
v3.6.10
v3.6.11
v3.6.2
v3.6.3
v3.6.4
v3.6.5
v3.6.6
v3.6.7
v3.6.8
v3.6.9
v3.7.0
v3.7.0-rc1
v3.7.0-rc2
v3.7.0-rc3
v3.7.0-rc4
v3.7.1
v3.7.10
v3.7.11
v3.7.12
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.7.6
v3.7.7
v3.7.8
v3.7.9
v4.*
v4.0.0
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.0.0-rc4
v4.0.1
v4.0.2
v4.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62157.json"