VYPR

Rancher

by SUSE S.A.

Source repositories

CVEs (39)

  • CVE-2021-36782CriSep 7, 2022
    risk 0.68cvss 9.9epss 0.03

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE…

  • CVE-2023-22651CriMay 4, 2023
    risk 0.64cvss 9.9epss 0.01

    Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources…

  • CVE-2022-43757CriFeb 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…

  • CVE-2021-36783CriSep 7, 2022
    risk 0.64cvss 9.9epss 0.01

    A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This…

  • CVE-2019-11202CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher…

  • CVE-2022-31247CriSep 7, 2022
    risk 0.59cvss 9.1epss 0.01

    An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…

  • CVE-2023-22649HigOct 16, 2024
    risk 0.58cvss 8.4epss 0.02

    A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have…

  • CVE-2020-10676HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

  • CVE-2023-22647CriJun 1, 2023
    risk 0.57cvss 9.9epss 0.01

    An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being…

  • CVE-2021-36776HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

  • CVE-2021-36775HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

  • CVE-2019-12303HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.02

    In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.

  • CVE-2019-12274HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.01

    In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive…

  • CVE-2017-7297HigMar 29, 2017
    risk 0.57cvss 8.8epss 0.01

    Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.

  • CVE-2022-21947HigApr 1, 2022
    risk 0.54cvss 8.3epss 0.01

    A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.

  • CVE-2019-6287HigApr 10, 2019
    risk 0.53cvss 8.1epss 0.01

    In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.

  • CVE-2023-22648HigJun 1, 2023
    risk 0.52cvss 8.0epss 0.00

    A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on…

  • CVE-2026-41053HigJun 30, 2026
    risk 0.50cvss 8.8epss 0.00

    Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

  • CVE-2026-41052HigJun 29, 2026
    risk 0.50cvss 8.8epss 0.00

    Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

  • CVE-2018-20321HigApr 10, 2019
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. This could be mitigated…

Page 1 of 2