Description
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type.
This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.
This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3361 | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b. |
Github GHSA |
GHSA-j5hq-5jcr-xwx7 | github.com/rancher/steve's users can issue watch commands for arbitrary resources |
References
History
Fri, 11 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b. | |
| Title | Users can issue watch commands for arbitrary resources | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-04-11T13:22:07.089Z
Reserved: 2024-11-06T12:19:57.723Z
Link: CVE-2024-52280
Updated: 2025-04-11T13:21:57.291Z
Status : Deferred
Published: 2025-04-11T12:15:14.433
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52280
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:07:52Z
Weaknesses
EUVD
Github GHSA