6.5
CVE-2021-32001
- EPSS 0.11%
- Published 28.07.2021 10:15:08
- Last modified 21.11.2024 06:06:41
- Source meissner@suse.de
- Teams watchlist Login
- Open Login
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s version v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 and prior versions; RKE2 version v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 and prior versions.
Data is provided by the National Vulnerability Database (NVD)
Suse ≫ Rancher K3s Version1.19.12
Suse ≫ Rancher K3s Version1.20.8
Suse ≫ Rancher K3s Version1.21.2
Suse ≫ Rancher Rke2 Version1.19.12
Suse ≫ Rancher Rke2 Version1.20.8
Suse ≫ Rancher Rke2 Version1.21.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.268 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
meissner@suse.de | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.