Suse

Rancher

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 04.03.2026 15:08:11
  • Zuletzt bearbeitet 05.03.2026 17:57:32

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

  • EPSS 0.02%
  • Veröffentlicht 25.02.2026 10:49:29
  • Zuletzt bearbeitet 25.02.2026 14:15:29

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

  • EPSS 0.01%
  • Veröffentlicht 25.02.2026 10:36:57
  • Zuletzt bearbeitet 03.03.2026 16:26:32

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA cer...

  • EPSS 0.01%
  • Veröffentlicht 29.10.2025 14:58:06
  • Zuletzt bearbeitet 30.10.2025 15:03:13

A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.

  • EPSS 0.01%
  • Veröffentlicht 29.10.2025 14:54:04
  • Zuletzt bearbeitet 30.10.2025 15:03:13

A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles th...

  • EPSS 0.01%
  • Veröffentlicht 02.10.2025 12:15:28
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s auth...

  • EPSS 0.02%
  • Veröffentlicht 02.10.2025 12:15:28
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.

  • EPSS 0.01%
  • Veröffentlicht 02.10.2025 10:15:39
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or ...

  • EPSS 0.03%
  • Veröffentlicht 02.09.2025 11:53:03
  • Zuletzt bearbeitet 02.09.2025 15:55:25

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessivel...

  • EPSS 0.02%
  • Veröffentlicht 02.09.2025 11:49:49
  • Zuletzt bearbeitet 02.09.2025 15:55:25

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.