Impact
The reported flaw involves incorrect credential cleaning when a user logs out of SUSE Rancher. Because the logout process does not fully invalidate or delete stored authentication tokens, an attacker that has previously obtained credentials can continue to use those same credentials after the account has been logged out. This allows any subsequent use of the session, including access to administrative functions or data, to proceed without requiring a fresh login. The vulnerability is an example of a session management weakness (CWE‑613) that can enable attackers to maintain unauthorized access after a user has ended a session.
Affected Systems
The affected product is SUSE Rancher. Versions prior to 2.15.2 are impacted. Administrators using Rancher 2.15 or earlier must verify whether they are using a version before the 2.15.2 release and apply the necessary update if so.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw. Even though the EPSS score is not available, the lack of exploitation complexity and the remote nature of the flaw suggest that attackers could exploit it by simply logging in and then logging out, or by triggering a logout action via crafted requests. This vulnerability is not yet listed in the CISA KEV catalog, but its high CVSS and potential for persistent unauthorized access mean that it should be treated as a high‑risk issue. It is inferred that an attacker can achieve continued access after logout, possibly leading to further compromise depending on the user’s privileges.
OpenCVE Enrichment