CVE-2024-52282 — Sensitive Information Exposure in Rancher
Severity
6.2MEDIUMNVD
EPSS
0.1%
top 76.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Description
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET
access to the Rancher Manager Apps Catalog to read any sensitive information that are
contained within the Apps’ values. Additionally, the same information
leaks into auditing logs when the audit level is set to equal or above
2.
This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:NExploitability: 1.7 | Impact: 4.0
Affected Packages2 packages
🔴Vulnerability Details
4OSV
▶