« Volver al listado

Suse

Suse Rancher: vulnerabilidades y CVE

Suse Rancher tiene 46 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE46
Últimos 12 meses11
Críticas10
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-88805Alta (8.1)0.25%—28 sept 2026
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
CVE-2026-88804Crítica (9.6)0.54%—28 sept 2026
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before…
CVE-2026-75035Alta (7.1)0.34%—3 sept 2026
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty…
CVE-2026-75034Alta (7.4)0.32%—3 sept 2026
A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that…
CVE-2026-75033Alta (7.7)0.34%—3 sept 2026
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same…
CVE-2026-71404Alta (8.7)0.42%—3 sept 2026
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without…
CVE-2026-71403Media (6.1)0.37%—3 sept 2026
A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io`…
CVE-2026-44946Crítica (9.5)0.39%—30 jun 2026
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher,…
CVE-2026-41053Alta (8.8)0.52%—30 jun 2026
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
CVE-2026-41052Crítica (9.4)0.42%—29 jun 2026
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVE-2025-67601Media (4.8)0.16%—25 feb 2026
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the…
CVE-2024-52281Alta (8.9)0.55%—16 abr 2025
A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher:…
CVE-2023-32197Alta (7.5)0.61%—16 abr 2025
A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14,…
CVE-2024-52280Alta (7.7)0.47%—11 abr 2025
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the…
CVE-2025-23391Crítica (9.1)0.46%—11 abr 2025
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before…
CVE-2025-23389Alta (8.4)0.47%—11 abr 2025
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0…
CVE-2025-23388Alta (8.2)0.59%—11 abr 2025
A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
CVE-2025-23387Media (5.3)0.58%—11 abr 2025
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token…
CVE-2024-52282Media (6.2)0.45%—11 abr 2025
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained…
CVE-2023-22649Alta (8.4)2.0%—16 oct 2024
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit…
CVE-2020-10676Alta (8.8)1.0%—12 dic 2023
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
CVE-2023-22648Alta (8.8)0.45%—1 jun 2023
A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their…
CVE-2023-22647Alta (8)0.71%—1 jun 2023
An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted,…
CVE-2022-43760Alta (8.4)0.71%—1 jun 2023
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another…
CVE-2023-22651Crítica (9.9)0.78%—4 may 2023
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component…
CVE-2022-43759Alta (8.8)0.68%—7 feb 2023
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher…
CVE-2022-43758Media (6.8)0.98%—7 feb 2023
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying…
CVE-2022-43757Alta (8.8)0.55%—7 feb 2023
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher…
CVE-2022-43755Crítica (9.8)1.7%—7 feb 2023
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher…
CVE-2022-21953Alta (8.8)0.47%—7 feb 2023
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to…

Otros productos de Suse