6.2

CVE-2024-52282

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET
 access to the Rancher Manager Apps Catalog to read any sensitive information that are 
contained within the Apps’ values. Additionally, the same information 
leaks into auditing logs when the audit level is set to equal or above 
2.

This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorSUSE
Product rancher
Default Statusunaffected
Version < 2.8.10
Version 2.8.0
Status affected
Version < 2.9.4
Version 2.9.0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.075
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
meissner@suse.de 6.2 1.7 4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.