Suse Rancher vulnerabilities
72 known vulnerabilities affecting suse/rancher.
Total CVEs
72
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH37MEDIUM21
Vulnerabilities
Page 4 of 4
CVE-2021-4200P4MEDIUMCVSS 5.4fixed in 2.5.13≥ 2.6.0, < 2.6.4+2 more2022-05-02
CVE-2021-4200 [MEDIUM] CWE-269 CVE-2021-4200: A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
nvd
CVE-2025-23387P4MEDIUMCVSS 5.3≥ 2.8.0, < 2.8.13≥ 2.9.0, < 2.9.7+1 more2025-04-11
CVE-2025-23387 [MEDIUM] CWE-200 CVE-2025-23387: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed u
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
nvd
CVE-2019-13209P4MEDIUMCVSS 6.1≥ 2.0.0, ≤ 2.2.42019-09-04
CVE-2019-13209 [MEDIUM] CWE-79 CVE-2019-13209: Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an expl
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands ag
nvd
CVE-2024-52282P4MEDIUMCVSS 6.2≥ 2.8.0, < 2.8.10≥ 2.9.0, < 2.9.42025-04-11
CVE-2024-52282 [MEDIUM] CWE-200 CVE-2024-52282: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET
access to the Rancher Manager Apps Catalog to read any sensitive information that are
contained within the Apps’ values. Additionally, the same information
leaks into auditing logs when the audit level is set to equal or above
2.
Th
nvd
CVE-2025-62879P4MEDIUMCVSS 4.9≥ 9.0.0, < 9.0.1≥ 8.0.0, < 8.1.2+2 more2026-03-04
CVE-2025-62879 [MEDIUM] CWE-532 CVE-2025-62879: A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
nvd
CVE-2026-44934P4HIGHCVSS 7.0≥ 1.0.0, < 1.0.22026-07-06
CVE-2026-44934 [HIGH] CWE-215 CVE-2026-44934: A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.
nvd
CVE-2021-25313P4MEDIUMCVSS 6.1fixed in 2.5.6≥ Rancher, < 2.5.62021-03-05
CVE-2021-25313 [MEDIUM] CWE-79 CVE-2021-25313: A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
nvd
CVE-2019-11881P4MEDIUMCVSS 4.7v2.1.42019-06-10
CVE-2019-11881 [MEDIUM] CVE-2019-11881: A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter
A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "Th
nvd
CVE-2025-67601P4MEDIUMCVSS 4.8≥ 2.10.0, < 2.10.11≥ 2.11.0, < 2.11.10+3 more2026-02-25
CVE-2025-67601 [MEDIUM] CWE-295 CVE-2025-67601: A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
nvd
CVE-2025-54468P4MEDIUMCVSS 4.7≥ 2.12.0, < 2.12.2≥ 2.11.0, < 2.11.6+2 more2025-10-02
CVE-2025-54468 [MEDIUM] CWE-200 CVE-2025-54468: A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.
nvd
CVE-2024-58269P4MEDIUMCVSS 4.3fixed in 0.0.0-20251013203444-50dc516a19ea2025-10-29
CVE-2024-58269 [MEDIUM] CWE-532 CVE-2024-58269: A vulnerability has been identified in Rancher Manager, where sensitive information, including secr
A vulnerability has been identified in Rancher Manager, where sensitive
information, including secret data, cluster import URLs, and
registration tokens, is exposed to any entity with access to Rancher
audit logs.
nvd
CVE-2023-32199P4MEDIUMCVSS 4.3fixed in 0.0.0-20251014212116-7faa74a968c22025-10-29
CVE-2023-32199 [MEDIUM] CWE-281 CVE-2023-32199: A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRol
A vulnerability has been identified within Rancher
Manager, where after removing a custom GlobalRole that gives
administrative access or the corresponding binding, the user still
retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
nvd
← Previous4 / 4