VYPR

apk package

chainguard/harvester-fips-webhook

pkg:apk/chainguard/harvester-fips-webhook

Vulnerabilities (60)

  • CVE-2025-23389HigApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

  • CVE-2025-23388HigApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

  • CVE-2025-23387MedApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from

  • CVE-2024-52282MedApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information le

  • CVE-2024-7598LowMar 20, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for

  • CVE-2025-1767MedMar 13, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using t

  • CVE-2024-36623HigNov 29, 2024
    affected < 1.8.1-r11fixed 1.8.1-r11

    moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

  • CVE-2022-45157CriNov 13, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being st

  • CVE-2024-22032MedOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written in plaintext on the AppliedSpec. Cluster owners, Cluster members, and Project me

  • CVE-2024-22030HigOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this

  • CVE-2023-32196MedOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.

  • CVE-2023-32194HigOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or dele

  • CVE-2023-22650HigOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which m

  • CVE-2023-22649HigOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have i

  • CVE-2024-33394MedMay 2, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2024-31420MedApr 3, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the vi

  • CVE-2021-36776HigApr 4, 2022
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

  • CVE-2020-8912LowAug 11, 2020
    affected < 0fixed 0

    A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-

  • CVE-2020-8911MedAug 11, 2020
    affected < 0fixed 0

    A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket a

  • CVE-2019-13209MedSep 4, 2019
    affected < 0fixed 0

    Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter.

Page 3 of 3