Description
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23366 | A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13. |
Github GHSA |
GHSA-8w87-58w6-hfv8 | Rancher doesn't properly sanitize credentials in cluster template answers |
References
History
No history.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-09-16T18:13:16.201Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36783
No data.
Status : Modified
Published: 2022-09-07T09:15:08.600
Modified: 2024-11-21T06:14:05.463
Link: CVE-2021-36783
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA