cbcvebase.

Suse Rancher vulnerabilities

80 known vulnerabilities affecting suse/rancher.

Total CVEs
80
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH41MEDIUM24

Vulnerabilities

Page 4 of 4
CVE-2022-43760P3HIGHCVSS 8.4≥ 2.6.0, < 2.6.13≥ 2.7.0, < 2.7.4+2 more2023-06-01
CVE-2022-43760 [HIGH] CWE-79 CVE-2022-43760: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behal
nvd
CVE-2023-32196P3MEDIUMCVSS 6.6≥ 2.7.0, < 2.7.14≥ 2.8.0, < 2.8.52024-10-16
CVE-2023-32196 [MEDIUM] CWE-269 CVE-2023-32196: A vulnerability has been identified whereby privilege escalation checks are not properly enforced fo A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.
nvd
CVE-2021-32001P3MEDIUMCVSS 6.5≥ K3s, ≤ v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1≥ RKE2, ≤ v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r12021-07-28
CVE-2021-32001 [MEDIUM] CWE-311 CVE-2021-32001: K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore ba K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s ve
nvd
CVE-2026-44948P3MEDIUMCVSS 5.3≥ 0.12.0, < 0.12.16≥ 0.13.0, < 0.13.12+2 more2026-06-30
CVE-2026-44948 [MEDIUM] CWE-23 CVE-2026-44948: A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up t A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.
nvd
CVE-2026-71403P4MEDIUMCVSS 6.1fixed in 2.15.12026-09-03
CVE-2026-71403 [MEDIUM] CWE-639 CVE-2026-71403: A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a Use A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to
nvd
CVE-2026-44936P4MEDIUMCVSS 5.0≥ 0.15.0, < 0.15.2≥ 0.14.0, < 0.14.6+2 more2026-07-06
CVE-2026-44936 [MEDIUM] CWE-918 CVE-2026-44936: Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fl Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able t
nvd
CVE-2021-4200P4MEDIUMCVSS 5.4fixed in 2.5.13≥ 2.6.0, < 2.6.4+2 more2022-05-02
CVE-2021-4200 [MEDIUM] CWE-269 CVE-2021-4200: A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
nvd
CVE-2025-23387P4MEDIUMCVSS 5.3≥ 2.8.0, < 2.8.13≥ 2.9.0, < 2.9.7+1 more2025-04-11
CVE-2025-23387 [MEDIUM] CWE-200 CVE-2025-23387: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed u A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
nvd
CVE-2026-55998P4MEDIUMCVSS 5.3≥ 2.14.0, < 2.14.4≥ 2.13.0, < 2.13.8+2 more2026-08-05
CVE-2026-55998 [MEDIUM] CWE-204 CVE-2026-55998: The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist,
nvd
CVE-2019-13209P4MEDIUMCVSS 6.1≥ 2.0.0, ≤ 2.2.42019-09-04
CVE-2019-13209 [MEDIUM] CWE-79 CVE-2019-13209: Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an expl Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands ag
nvd
CVE-2024-52282P4MEDIUMCVSS 6.2≥ 2.8.0, < 2.8.10≥ 2.9.0, < 2.9.42025-04-11
CVE-2024-52282 [MEDIUM] CWE-200 CVE-2024-52282: A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information leaks into auditing logs when the audit level is set to equal or above 2. Th
nvd
CVE-2025-62879P4MEDIUMCVSS 4.9≥ 9.0.0, < 9.0.1≥ 8.0.0, < 8.1.2+2 more2026-03-04
CVE-2025-62879 [MEDIUM] CWE-532 CVE-2025-62879: A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
nvd
CVE-2026-44934P4HIGHCVSS 7.0≥ 1.0.0, < 1.0.22026-07-06
CVE-2026-44934 [HIGH] CWE-215 CVE-2026-44934: A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.
nvd
CVE-2021-25313P4MEDIUMCVSS 6.1fixed in 2.5.6≥ Rancher, < 2.5.62021-03-05
CVE-2021-25313 [MEDIUM] CWE-79 CVE-2021-25313: A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
nvd
CVE-2019-11881P4MEDIUMCVSS 4.7v2.1.42019-06-10
CVE-2019-11881 [MEDIUM] CVE-2019-11881: A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "Th
nvd
CVE-2025-67601P4MEDIUMCVSS 4.8≥ 2.10.0, < 2.10.11≥ 2.11.0, < 2.11.10+3 more2026-02-25
CVE-2025-67601 [MEDIUM] CWE-295 CVE-2025-67601: A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
nvd
CVE-2025-54468P4MEDIUMCVSS 4.7≥ 2.12.0, < 2.12.2≥ 2.11.0, < 2.11.6+2 more2025-10-02
CVE-2025-54468 [MEDIUM] CWE-200 CVE-2025-54468: A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.
nvd
CVE-2024-58269P4MEDIUMCVSS 4.3fixed in 0.0.0-20251013203444-50dc516a19ea2025-10-29
CVE-2024-58269 [MEDIUM] CWE-532 CVE-2024-58269: A vulnerability has been identified in Rancher Manager, where sensitive information, including secr A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.
nvd
CVE-2023-32199P4MEDIUMCVSS 4.3fixed in 0.0.0-20251014212116-7faa74a968c22025-10-29
CVE-2023-32199 [MEDIUM] CWE-281 CVE-2023-32199: A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRol A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
nvd
CVE-2026-55996P4MEDIUMCVSS 4.3≥ 2.11.0, < 2.11.16≥ 2.12.0, < 2.12.12+2 more2026-08-05
CVE-2026-55996 [MEDIUM] CWE-770 CVE-2026-55996: A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the catt A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate
nvd
Suse Rancher vulnerabilities | cvebase