Suse

Rancher

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.75%
  • Veröffentlicht 05.08.2026 10:00:04
  • Zuletzt bearbeitet 06.08.2026 05:17:03

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane a...

  • EPSS 0.21%
  • Veröffentlicht 05.08.2026 07:51:21
  • Zuletzt bearbeitet 05.08.2026 14:17:08

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/priv...

  • EPSS 0.43%
  • Veröffentlicht 05.08.2026 07:49:11
  • Zuletzt bearbeitet 05.08.2026 14:17:08

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimiting...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 07:46:43
  • Zuletzt bearbeitet 05.08.2026 20:17:11

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without ...

  • EPSS 0.36%
  • Veröffentlicht 07.07.2026 13:05:03
  • Zuletzt bearbeitet 08.07.2026 05:16:27

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An ...

  • EPSS 0.38%
  • Veröffentlicht 06.07.2026 09:52:18
  • Zuletzt bearbeitet 09.07.2026 20:24:49

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a do...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 06.07.2026 09:30:20
  • Zuletzt bearbeitet 09.07.2026 20:34:30

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (B...

  • EPSS 0.11%
  • Veröffentlicht 06.07.2026 08:45:26
  • Zuletzt bearbeitet 06.07.2026 19:46:02

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentia...

  • EPSS 0.41%
  • Veröffentlicht 02.07.2026 16:00:06
  • Zuletzt bearbeitet 06.07.2026 12:44:21

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenant...

  • EPSS 0.29%
  • Veröffentlicht 30.06.2026 15:12:17
  • Zuletzt bearbeitet 02.07.2026 17:45:44

A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a de...