Impact
When the DEBUG log level is enabled in SUSE Rancher AI Agent flaw creates an information disclosure that could allow an attacker with access to the agent’s logs to obtain credentials or confidential information, potentially compromising the services the agent interacts with. The weakness corresponds to inappropriate handling of sensitive data in logging (CWE-215).
Affected Systems
The vulnerability affects SUSE Rancher AI Agent versions earlier than 1.0.2. Users running a local instance of the agent can trigger DEBUG mode by configuring the log level and subsequently exposed tokens.
Risk and Exploitability
The CVSS score of 7 reflects a medium to high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is local; an attacker would need local access to the agent to enable DEBUG logging and read the agent’s logs to misuse any exposed credentials.
OpenCVE Enrichment