Impact
The vulnerability in the rancher-extension-stackstate extension causes service tokens to be stored or displayed in plain text, allowing any attacker who already has limited access to read them. With the token, an attacker can gain unauthorized entry to the observability platform or elevate privileges, potentially accessing sensitive metrics or configuration data. This is a confidentiality breach (CWE-200) and an insecure transmission issue (CWE-312).
Affected Systems
Affected are systems running SUSE Observability that deploy the rancher-extension-stackstate component. No specific product versions are listed, so any environment using the extension is at risk until a corrective action is taken.
Risk and Exploitability
The CVSS score of 5.7 places the issue in the medium range while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires an attacker who already has some level of access to the host or Kubernetes cluster; through that foothold, the exposed token can be harvested to gain broader access within the observability environment.
OpenCVE Enrichment