Severity
7.5HIGHNVD
CNA7.3
EPSS
0.4%
top 39.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2

Description

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5suse/rancherRancher2.5.12+1
NVDsuse/rancher2.6.02.6.3+1
Gogithub.com/rancher_rancher2.6.02.6.3+1

🔴Vulnerability Details

3
OSV
Exposure of repository credentials to external third-party sources in Rancher2022-05-02
CVEList
Exposure of repository credentials to external third-party sources2022-05-02
GHSA
Exposure of repository credentials to external third-party sources in Rancher2022-05-02
CVE-2021-36778 — Incorrect Authorization in Rancher | cvebase