cbcvebase.

Suse Rancher vulnerabilities

72 known vulnerabilities affecting suse/rancher.

Total CVEs
72
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH37MEDIUM21

Vulnerabilities

Page 3 of 4
CVE-2023-22647P3HIGHCVSS 8.0≥ 2.6.0, < 2.6.13≥ 2.7.0, < 2.7.4+2 more2023-06-01
CVE-2023-22647 [HIGH] CWE-267 CVE-2023-22647: An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage th An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. When this operation was followed-up by other specially crafted command
nvd
CVE-2024-22030P3HIGHCVSS 8.0≥ 2.7.0, < 2.7.15≥ 2.8.0, < 2.8.8+1 more2024-10-16
CVE-2024-22030 [HIGH] CWE-295 CVE-2024-22030: A vulnerability has been identified within Rancher that can be exploited in narrow circumstances th A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL.
nvd
CVE-2024-52280P3HIGHCVSS 7.7fixed in 2175e09fixed in 6e30359+1 more2025-04-11
CVE-2024-52280 [HIGH] CWE-200 CVE-2024-52280: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which al A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.
nvd
CVE-2026-44949P3HIGHCVSS 7.0≥ 0.7.0, < 0.7.10≥ 0.8.0, < 0.8.7+2 more2026-06-30
CVE-2026-44949 [HIGH] CWE-306 CVE-2026-44949: A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handle A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission payload and cause workspace-related
nvd
CVE-2024-52284P3HIGHCVSS 7.7≥ 0.13.0, < 0.13.1-0.20250806151509-088bcbea7edb≥ 0.12.0, < 0.12.6+1 more2025-09-02
CVE-2024-52284 [HIGH] CWE-312 CVE-2024-52284: Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeplo Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
nvd
CVE-2024-58260P3HIGHCVSS 7.6≥ 2.12.0, < 2.12.2≥ 2.11.0, < 2.11.6+2 more2025-10-02
CVE-2024-58260 [HIGH] CWE-863 CVE-2024-58260: A vulnerability has been identified within Rancher Manager where a missing server-side validation on A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
nvd
CVE-2021-36784P3HIGHCVSS 7.2fixed in 2.5.13≥ 2.6.0, < 2.6.4+2 more2022-05-02
CVE-2021-36784 [HIGH] CWE-269 CVE-2021-36784: A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
nvd
CVE-2023-32194P3HIGHCVSS 7.2≥ 2.6.0, < 2.6.14≥ 2.7.0, < 2.7.10+1 more2024-10-16
CVE-2023-32194 [HIGH] CWE-269 CVE-2023-32194: A vulnerability has been identified when granting a create or * global role for a resource type of " A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project.
nvd
CVE-2022-43756P3HIGHCVSS 7.5≥ wrangler, ≤ 0.7.32023-02-07
CVE-2022-43756 [HIGH] CWE-74 CVE-2022-43756: A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of service by supplying specially crafted git credentials. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler version 0.8.4 and prior versions; wrang
nvd
CVE-2019-6287P3HIGHCVSS 8.1≥ 2.0.0, ≤ 2.1.52019-04-10
CVE-2019-6287 [HIGH] CWE-269 CVE-2019-6287: In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and d In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
nvd
CVE-2022-43758P3MEDIUMCVSS 6.8≥ 2.5.0, < 2.5.17≥ 2.6.0, < 2.6.10+2 more2023-02-07
CVE-2022-43758 [MEDIUM] CWE-78 CVE-2022-43758: A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnera A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Rancher Rancher versions prior to 2.5
nvd
CVE-2022-21951P3MEDIUMCVSS 6.8≥ 2.5.0, < 2.5.14≥ 2.6.0, < 2.6.5+2 more2022-05-25
CVE-2022-21951 [MEDIUM] CWE-319 CVE-2022-21951: A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows atta A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden This issue affects: SUSE Rancher Rancher versions prior to
nvd
CVE-2023-32197P3MEDIUMCVSS 6.6≥ 2.7.0, < 2.7.14≥ 2.8.0, < 2.8.52025-04-16
CVE-2023-32197 [MEDIUM] CWE-269 CVE-2023-32197: A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=t A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.
nvd
CVE-2024-22032P3MEDIUMCVSS 6.5≥ 2.7.0, < 2.7.14≥ 2.8.0, < 2.8.52024-10-16
CVE-2024-22032 [MEDIUM] CWE-200 CVE-2024-22032: A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secr A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written in plaintext on the AppliedSpec. Cluster owners, Cluster members, and Project members (for projects within the cluster), all have RBAC permissions to view
nvd
CVE-2022-43760P3HIGHCVSS 8.4≥ 2.6.0, < 2.6.13≥ 2.7.0, < 2.7.4+2 more2023-06-01
CVE-2022-43760 [HIGH] CWE-79 CVE-2022-43760: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behal
nvd
CVE-2026-44947P3MEDIUMCVSS 6.9≥ 2.13.0, < 2.13.7≥ 2.14.0, < 2.14.32026-06-30
CVE-2026-44947 [MEDIUM] CWE-281 CVE-2026-44947: A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher version A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.
nvd
CVE-2023-32196P3MEDIUMCVSS 6.6≥ 2.7.0, < 2.7.14≥ 2.8.0, < 2.8.52024-10-16
CVE-2023-32196 [MEDIUM] CWE-269 CVE-2023-32196: A vulnerability has been identified whereby privilege escalation checks are not properly enforced fo A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.
nvd
CVE-2021-32001P3MEDIUMCVSS 6.5≥ K3s, ≤ v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1≥ RKE2, ≤ v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r12021-07-28
CVE-2021-32001 [MEDIUM] CWE-311 CVE-2021-32001: K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore ba K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s ve
nvd
CVE-2026-44948P3MEDIUMCVSS 5.3≥ 0.12.0, < 0.12.16≥ 0.13.0, < 0.13.12+2 more2026-06-30
CVE-2026-44948 [MEDIUM] CWE-23 CVE-2026-44948: A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up t A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.
nvd
CVE-2026-44936P4MEDIUMCVSS 5.0≥ 0.15.0, < 0.15.2≥ 0.14.0, < 0.14.6+2 more2026-07-06
CVE-2026-44936 [MEDIUM] CWE-918 CVE-2026-44936: Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fl Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able t
nvd
Suse Rancher vulnerabilities | cvebase