cbcvebase.
CVE-2024-52284
published 2025-09-02

CVE-2024-52284: Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing…

PriorityP341high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
0.22%
12.2th percentile
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

Affected

6 ranges
VendorProductVersion rangeFixed in
github.comrancher_fleet>= 0.11.0 < 0.11.100.11.10
github.comrancher_fleet>= 0.12.0 < 0.12.60.12.6
github.comrancher_fleet>= 0.13.0 < 0.13.1-0.20250806151509-088bcbea7edb0.13.1-0.20250806151509-088bcbea7edb
suserancher>= 0.11.0 < 0.11.100.11.10
suserancher>= 0.12.0 < 0.12.60.12.6
suserancher>= 0.13.0 < 0.13.1-0.20250806151509-088bcbea7edb0.13.1-0.20250806151509-088bcbea7edb

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
osv7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.