CVE-2022-43755Insufficient Entropy in Rancher

Severity
9.8CRITICALNVD
CNA7.1GHSA9.9OSV9.9
EPSS
0.3%
top 43.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7

Description

A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5suse/rancherRancher2.6.10
NVDsuse/rancher2.6.02.6.10+1
Gogithub.com/rancher_rancher2.6.02.6.10+1

Patches

🔴Vulnerability Details

3
CVEList
Rancher: Non-random authentication token2023-02-07
GHSA
Rancher cattle-token is predictable2023-01-25
OSV
Rancher cattle-token is predictable2023-01-25
CVE-2022-43755 — Insufficient Entropy in Suse Rancher | cvebase