Suse

Rancher

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 16.04.2025 08:40:54
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.

  • EPSS 0.17%
  • Veröffentlicht 16.04.2025 08:37:54
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is possible based...

  • EPSS 0.01%
  • Veröffentlicht 16.04.2025 08:31:11
  • Zuletzt bearbeitet 16.04.2025 13:25:37

A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.

  • EPSS 0.2%
  • Veröffentlicht 11.04.2025 11:12:44
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects ranche...

  • EPSS 0.08%
  • Veröffentlicht 11.04.2025 10:57:55
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Addition...

  • EPSS 0.24%
  • Veröffentlicht 11.04.2025 10:52:44
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: f...

  • EPSS 0.42%
  • Veröffentlicht 11.04.2025 10:48:51
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

  • EPSS 0.13%
  • Veröffentlicht 11.04.2025 10:46:43
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before ...

  • EPSS 0.34%
  • Veröffentlicht 11.04.2025 10:38:43
  • Zuletzt bearbeitet 11.04.2025 15:39:52

A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, fro...

  • EPSS 0.07%
  • Veröffentlicht 13.11.2024 14:15:14
  • Zuletzt bearbeitet 13.11.2024 17:01:16

A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere ...