CVE-2022-21947Resource Exposure in Rancher

CWE-668Resource Exposure2 documents2 sources
Severity
8.8HIGHNVD
CNA8.3
EPSS
0.1%
top 73.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1

Description

A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5suse/rancherDesktopV

🔴Vulnerability Details

1
CVEList
rancher desktop: Dashboard API is network accessible2022-04-01
CVE-2022-21947 — Resource Exposure in Suse Rancher | cvebase