Impact
A flaw in Rancher Manager causes the token store API to drop its internal owner filter when a non-administrative user supplies a label selector that references another user. As a result, any authenticated user can list and watch every other user's tokens, revealing token metadata and a salted hash of the bearer token. This constitutes a confidentiality breach that allows attackers to glean valuable authentication information. The weakness is identified as CWE-639.
Affected Systems
The vulnerability exists in SUSE Rancher Manager versions prior to 2.15.1. Administrators and non-administrative users of these versions are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity vulnerability. The EPSS score is unavailable, and the issue has not yet been listed in CISA KEV, suggesting limited but possible exploitation in the short term. Attackers must be authenticated, but the flaw allows an attacker with any valid user credential to enumerate tokens owned by other users through the ext.cattle.io/v1 token store API. No elevated privileges or code execution are required—information disclosure is the primary risk.
OpenCVE Enrichment