Suse

Rancher

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 29.10.2025 14:58:06
  • Zuletzt bearbeitet 30.10.2025 15:03:13

A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.

  • EPSS 0.01%
  • Veröffentlicht 29.10.2025 14:54:04
  • Zuletzt bearbeitet 30.10.2025 15:03:13

A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles th...

  • EPSS 0.01%
  • Veröffentlicht 02.10.2025 12:15:28
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s auth...

  • EPSS 0.02%
  • Veröffentlicht 02.10.2025 12:15:28
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.

  • EPSS 0.01%
  • Veröffentlicht 02.10.2025 10:15:39
  • Zuletzt bearbeitet 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or ...

  • EPSS 0.02%
  • Veröffentlicht 02.09.2025 11:53:03
  • Zuletzt bearbeitet 02.09.2025 15:55:25

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessivel...

  • EPSS 0.02%
  • Veröffentlicht 02.09.2025 11:49:49
  • Zuletzt bearbeitet 02.09.2025 15:55:25

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

  • EPSS 0.01%
  • Veröffentlicht 16.04.2025 08:40:54
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.

  • EPSS 0.12%
  • Veröffentlicht 16.04.2025 08:37:54
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is possible based...

  • EPSS 0.02%
  • Veröffentlicht 16.04.2025 08:31:11
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.