cbcvebase.
CVE-2021-36782
published 2022-09-07

CVE-2021-36782: A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project…

PriorityP264critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
2.93%
85.3th percentile
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.

Affected

9 ranges
VendorProductVersion rangeFixed in
github.comrancher_rancher>= 2.5.0 < 2.5.172.5.17
github.comrancher_rancher>= 2.5.0 < 2.5.162.5.16
github.comrancher_rancher>= 2.6.0 < 2.6.102.6.10
github.comrancher_rancher>= 2.6.0 < 2.6.72.6.7
github.comrancher_rancher>= 2.7.0 < 2.7.12.7.1
suserancher>= 2.5.0 < 2.5.162.5.16
suserancher>= 2.6.0 < 2.6.72.6.7
suserancher>= Rancher < 2.5.162.5.16
suserancher>= Rancher < 2.6.72.6.7

Detection & IOCsextracted from sources · hover to see the quote

urlcluster.management.cattle.io
  • Monitor Kubernetes API read access to cluster.management.cattle.io objects, which may indicate attempts to retrieve plaintext credentials, API keys, or service account tokens stored on Cluster objects in Rancher.
  • A Metasploit auxiliary module exists for this CVE (rancher_authenticated_api_cred_exposure). Detect exploitation attempts by monitoring for authenticated API enumeration of Rancher cluster objects, particularly GET requests to cluster management API endpoints by low-privileged roles (Cluster Members, Project Members, User Base).
  • ·Affected versions are Rancher prior to 2.5.16 and prior to 2.6.7. Instances running Rancher 2.5.15 or earlier, and 2.6.6 or earlier, are vulnerable to plaintext credential exposure via the Kubernetes API.
  • ·Sensitive fields including passwords, API keys, and Rancher's service account token used to provision clusters are stored in plaintext on Kubernetes Cluster objects, accessible to any authenticated user with read access.

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
ghsa9.9CRITICAL
osv9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.