Suse

Rancher

82 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 03.09.2026 14:51:44
  • Zuletzt bearbeitet 18.09.2026 14:58:34

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with deleg...

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 14:45:37
  • Zuletzt bearbeitet 18.09.2026 15:03:02

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity pr...

  • EPSS 0.75%
  • Veröffentlicht 05.08.2026 10:00:04
  • Zuletzt bearbeitet 01.09.2026 20:54:51

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane a...

  • EPSS 0.21%
  • Veröffentlicht 05.08.2026 07:51:21
  • Zuletzt bearbeitet 01.09.2026 20:54:51

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/priv...

  • EPSS 0.43%
  • Veröffentlicht 05.08.2026 07:49:11
  • Zuletzt bearbeitet 01.09.2026 20:54:51

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimiting...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 07:46:43
  • Zuletzt bearbeitet 01.09.2026 20:54:51

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without ...

  • EPSS 0.36%
  • Veröffentlicht 07.07.2026 13:05:03
  • Zuletzt bearbeitet 08.07.2026 05:16:27

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An ...

  • EPSS 0.38%
  • Veröffentlicht 06.07.2026 09:52:18
  • Zuletzt bearbeitet 09.07.2026 20:24:49

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a do...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 06.07.2026 09:30:20
  • Zuletzt bearbeitet 09.07.2026 20:34:30

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (B...

  • EPSS 0.11%
  • Veröffentlicht 06.07.2026 08:45:26
  • Zuletzt bearbeitet 06.07.2026 19:46:02

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentia...