CVE-2022-21953
- EPSS 0.07%
- Published 07.02.2023 13:15:09
- Last modified 21.11.2024 06:45:46
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior t...
CVE-2022-31247
- EPSS 0.35%
- Published 07.09.2022 09:15:08
- Last modified 21.11.2024 07:04:12
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage proj...
CVE-2021-36783
- EPSS 0.48%
- Published 07.09.2022 09:15:08
- Last modified 21.11.2024 06:14:05
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed...
CVE-2021-36782
- EPSS 79.61%
- Published 07.09.2022 09:15:08
- Last modified 21.11.2024 06:14:05
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. ...
CVE-2022-21951
- EPSS 0.08%
- Published 25.05.2022 09:15:08
- Last modified 21.11.2024 06:45:46
A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an R...
CVE-2021-4200
- EPSS 0.35%
- Published 02.05.2022 12:16:26
- Last modified 21.11.2024 06:37:07
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
CVE-2021-36784
- EPSS 0.48%
- Published 02.05.2022 12:16:26
- Last modified 21.11.2024 06:14:05
A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
CVE-2021-36778
- EPSS 0.38%
- Published 02.05.2022 12:16:25
- Last modified 21.11.2024 06:14:04
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior ...
CVE-2021-25313
- EPSS 0.65%
- Published 05.03.2021 09:15:13
- Last modified 21.11.2024 05:54:43
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
CVE-2019-13209
- EPSS 0.28%
- Published 04.09.2019 14:15:11
- Last modified 21.11.2024 04:24:27
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party...