cbcvebase.
CVE-2024-52280
published 2025-04-11

CVE-2024-52280: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to…

PriorityP342high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
0.44%
36.3th percentile
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.

Affected

4 ranges
VendorProductVersion rangeFixed in
github.comrancher_steve>= 0 < 0.0.0-20241029132712-2175e090fe4b0.0.0-20241029132712-2175e090fe4b
suserancher< 2175e092175e09
suserancher< 6e303596e30359
suserancher< c744f0bc744f0b
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.