Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c2hv-4pfj-mm2r | Argo Workflow may expose artifact repository credentials |
Fri, 06 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj argo Workflows
|
|
| CPEs | cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Argo Workflows Project
Argo Workflows Project argo Workflows |
Argoproj argo Workflows
|
Mon, 17 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argo Workflows Project
Argo Workflows Project argo Workflows |
|
| CPEs | cpe:2.3:a:argo_workflows_project:argo_workflows:*:*:*:*:*:kubernetes:*:* | |
| Vendors & Products |
Argo Workflows Project
Argo Workflows Project argo Workflows |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-workflows |
|
| Vendors & Products |
Argoproj
Argoproj argo-workflows |
Thu, 16 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist. | |
| Title | Argo Workflows exposes artifact repository credentials in workflow-controller logs | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-14T16:06:02.367Z
Reserved: 2025-10-07T16:12:03.424Z
Link: CVE-2025-62157
Updated: 2025-10-14T16:05:51.199Z
Status : Analyzed
Published: 2025-10-14T15:16:12.853
Modified: 2026-02-06T20:49:29.827
Link: CVE-2025-62157
OpenCVE Enrichment
Updated: 2025-10-20T15:49:40Z
Github GHSA