A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g7j7-h4q8-8w2f Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2024-09-17T04:14:05.504Z

Reserved: 2021-07-19T00:00:00

Link: CVE-2021-36782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-07T09:15:08.397

Modified: 2024-11-21T06:14:05.320

Link: CVE-2021-36782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.