High severity8.4NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2023-22649
CVE-2023-22649
Description
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. Rancher Audit Logging is an opt-in feature, only deployments that have it enabled and have AUDIT_LEVEL set to 1 or above are impacted by this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.6.0, < 2.6.14 | 2.6.14 |
github.com/rancher/rancherGo | >= 2.7.0, < 2.7.10 | 2.7.10 |
github.com/rancher/rancherGo | >= 2.8.0, < 2.8.2 | 2.8.2 |
Affected products
8- osv-coords5 versionspkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fipspkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester-webhookpkg:golang/github.com/rancher/rancher
< 1.8.1-r1+ 4 more
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r0
- (no CPE)range: < 1.8.1-r0
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: >= 2.6.0, < 2.6.14
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-xfj7-qf8w-2gcrghsaADVISORY
- github.com/rancher/rancher/security/advisories/GHSA-xfj7-qf8w-2gcrnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-22649ghsaADVISORY
- bugzilla.suse.com/show_bug.cginvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.