CVE-2024-52282Sensitive Information Exposure in Rancher

Severity
6.2MEDIUMNVD
EPSS
0.1%
top 76.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11

Description

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information leaks into auditing logs when the audit level is set to equal or above 2. This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:NExploitability: 1.7 | Impact: 4.0

Affected Packages2 packages

CVEListV5suse/rancher2.8.02.8.10+1
Gogithub.com/rancher_rancher2.8.02.8.10+1

🔴Vulnerability Details

4
CVEList
Rancher Helm Applications may have sensitive values leaked2025-04-11
OSV
Rancher Helm Applications may have sensitive values leaked in github.com/rancher/rancher2024-11-21
GHSA
Rancher Helm Applications may have sensitive values leaked2024-11-20
OSV
Rancher Helm Applications may have sensitive values leaked2024-11-20
CVE-2024-52282 — Sensitive Information Exposure | cvebase