7.7
CVE-2024-52284
- EPSS 0.03%
- Veröffentlicht 02.09.2025 11:49:49
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle meissner@suse.de
- CVE-Watchlists
- Unerledigt
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSUSE
≫
Produkt
Rancher
Default Statusunaffected
Version
0.13.0
Version <
0.13.1-0.20250806151509-088bcbea7edb
Status
affected
Version
0.12.0
Version <
0.12.6
Status
affected
Version
0.11.0
Version <
0.11.10
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| meissner@suse.de | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.