A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pods logs.
The product writes sensitive information to a log file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rancher_backup_and_restore_operator | Suse | 6.0.0 (including) | 6.0.3 (excluding) |
| Rancher_backup_and_restore_operator | Suse | 7.0.0 (including) | 7.0.5 (excluding) |
| Rancher_backup_and_restore_operator | Suse | 8.0.0 (including) | 8.1.2 (excluding) |
| Rancher_backup_and_restore_operator | Suse | 9.0.0 (including) | 9.0.1 (excluding) |