A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels) set to `1 or above` are impacted by this issue.

Subscriptions

Vendors Products
Rancher Subscribe
Rancher Subscribe
Rancher Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xfj7-qf8w-2gcr Rancher 'Audit Log' leaks sensitive information
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse rancher
CPEs cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:undefined
Vendors & Products Suse
Suse rancher

Wed, 16 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Rancher
Rancher rancher
CPEs cpe:2.3:a:rancher:rancher:*:*:*:*:*:*:*:*
Vendors & Products Rancher
Rancher rancher
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 08:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Wed, 16 Oct 2024 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels) set to `1 or above` are impacted by this issue.
Title Rancher 'Audit Log' leaks sensitive information
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2024-10-16T17:26:00.938Z

Reserved: 2023-01-05T10:40:08.605Z

Link: CVE-2023-22649

cve-icon Vulnrichment

Updated: 2024-10-16T16:28:57.600Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T08:15:04.390

Modified: 2024-10-30T21:08:46.247

Link: CVE-2023-22649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses