CVE-2022-43757Cleartext Storage of Sensitive Info in Rancher

Severity
8.8HIGHNVD
CNA9.9GHSA9.9OSV9.9
EPSS
0.2%
top 54.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7

Description

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5suse/rancherRancher2.5.17
NVDsuse/rancher2.5.02.5.17+2
Gogithub.com/rancher_rancher2.5.02.5.17+2

🔴Vulnerability Details

3
CVEList
Rancher: Exposure of sensitive fields2023-02-07
OSV
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects2023-01-25
GHSA
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects2023-01-25
CVE-2022-43757 — Cleartext Storage of Sensitive Info | cvebase