Suse

Rancher

47 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Published 02.10.2025 12:15:28
  • Last modified 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s auth...

  • EPSS 0.01%
  • Published 02.10.2025 12:15:28
  • Last modified 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.

  • EPSS 0.01%
  • Published 02.10.2025 10:15:39
  • Last modified 02.10.2025 19:11:46

A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or ...

  • EPSS 0.02%
  • Published 02.09.2025 11:53:03
  • Last modified 02.09.2025 15:55:25

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessivel...

  • EPSS 0.01%
  • Published 02.09.2025 11:49:49
  • Last modified 02.09.2025 15:55:25

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

  • EPSS 0.02%
  • Published 16.04.2025 08:40:54
  • Last modified 16.04.2025 13:25:37

A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.

  • EPSS 0.1%
  • Published 16.04.2025 08:37:54
  • Last modified 16.04.2025 13:25:37

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is possible based...

  • EPSS 0.01%
  • Published 16.04.2025 08:31:11
  • Last modified 16.04.2025 13:25:37

A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.

  • EPSS 0.04%
  • Published 11.04.2025 11:12:44
  • Last modified 11.04.2025 15:39:52

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects ranche...

  • EPSS 0.03%
  • Published 11.04.2025 10:57:55
  • Last modified 11.04.2025 15:39:52

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Addition...