<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Rancher (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/rancher.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rancher-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Rancher (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44543 – Local Path Provisioner provides a way for the Kubernetes users to utilize the lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44543</guid>
    <pubDate>Thu, 28 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44543</strong></p>
  <p>Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The helperPod.yaml template is loaded by the provisioner and used to create HelperPo…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25705 – A vulnerability has been identified in [Rancher's Extensions](https://rancherman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25705</guid>
    <pubDate>Wed, 13 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25705</strong></p>
  <p>A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to:  *  Overwrite Rancher binaries or configuration to inject code.    *…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67601 – A vulnerability has been identified within Rancher Manager, where using self-sig...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67601</guid>
    <pubDate>Wed, 25 Feb 2026 11:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67601</strong></p>
  <p>A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-58267 – A vulnerability has been identified within Rancher Manager whereby the SAML auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58267</guid>
    <pubDate>Thu, 02 Oct 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-58267</strong></p>
  <p>A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI  tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-58260 – A vulnerability has been identified within Rancher Manager where a missing serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58260</guid>
    <pubDate>Thu, 02 Oct 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-58260</strong></p>
  <p>A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-58259 – A vulnerability has been identified within Rancher Manager in which it 
did not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58259</guid>
    <pubDate>Tue, 02 Sep 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-58259</strong></p>
  <p>A vulnerability has been identified within Rancher Manager in which it  did not enforce request body size limits on certain public  (unauthenticated) and authenticated API endpoints. This allows a  malicious user to exploit this by sending excessively large payloads,  which are fully loaded into memory during processing, leading to Denial of Service (DoS).</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52281 – A: Improper Neutralization of Input During Web Page Generation vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52281</guid>
    <pubDate>Wed, 16 Apr 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52281</strong></p>
  <p>A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22036 – A vulnerability has been identified within Rancher where a cluster or node drive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22036</guid>
    <pubDate>Wed, 16 Apr 2025 09:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22036</strong></p>
  <p>A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot  jail and gain root access to the Rancher container itself. In  production environments, further privilege escalation is possible based  on living off the land within the Rancher container itself. For the test  and development environments, based on a –privileged Docker container,  i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52280 – A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52280</guid>
    <pubDate>Fri, 11 Apr 2025 12:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52280</strong></p>
  <p>A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher  which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type.  This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-23391 – A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restrict...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23391</guid>
    <pubDate>Fri, 11 Apr 2025 11:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-23391</strong></p>
  <p>A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23389 – A Improper Access Control vulnerability in SUSE rancher allows a local user to i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23389</guid>
    <pubDate>Fri, 11 Apr 2025 11:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23389</strong></p>
  <p>A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23388 – A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23388</guid>
    <pubDate>Fri, 11 Apr 2025 11:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23388</strong></p>
  <p>A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-45157 – A vulnerability has been identified in the way that Rancher stores vSphere's CPI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45157</guid>
    <pubDate>Wed, 13 Nov 2024 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-45157</strong></p>
  <p>A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside Rancher. This vulnerability is only applicable to users that deploy clusters in vSphe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22030 – A vulnerability has been identified within Rancher that can be exploited
 in nar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22030</guid>
    <pubDate>Wed, 16 Oct 2024 14:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22030</strong></p>
  <p>A vulnerability has been identified within Rancher that can be exploited  in narrow circumstances through a man-in-the-middle (MITM) attack. An  attacker would need to have control of an expired domain or execute a  DNS spoofing/hijacking attack against the domain to exploit this  vulnerability. The targeted domain is the one used as the Rancher URL.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22650 – A vulnerability has been identified in which Rancher does not automatically clea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22650</guid>
    <pubDate>Wed, 16 Oct 2024 09:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22650</strong></p>
  <p>A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22649 – A vulnerability has been identified which may lead to sensitive data being leake...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22649</guid>
    <pubDate>Wed, 16 Oct 2024 08:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22649</strong></p>
  <p>A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10676 – In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10676</guid>
    <pubDate>Tue, 12 Dec 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10676</strong></p>
  <p>In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22648 – A Improper Privilege Management vulnerability in SUSE Rancher causes permission ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22648</guid>
    <pubDate>Thu, 01 Jun 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22648</strong></p>
  <p>A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users  while they are logged in the Rancher UI. This would cause the users to  retain their previous permissions in Rancher, even if they change groups  on Azure AD, for example, to a lower privileged group, or are removed  from a group, thus retaining their access to Rancher…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-271</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22647 – An Improper Privilege Management vulnerability in SUSE Rancher allowed standard ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22647</guid>
    <pubDate>Thu, 01 Jun 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22647</strong></p>
  <p>An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local  cluster, resulting in the secret being deleted, but their read-level  permissions to the secret being preserved. When this operation was  followed-up by other specially crafted commands, it could result in the  user gaining acc…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43760 – An Improper Neutralization of Input During Web Page Generation ('Cross-site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43760</guid>
    <pubDate>Thu, 01 Jun 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43760</strong></p>
  <p>An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is  executed within another user's browser, allowing the attacker to steal  sensitive information, manipulate web content, or perform other  malicious activities on behalf of the victims. This could result in a…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22651 – Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Esc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22651</guid>
    <pubDate>Thu, 04 May 2023 08:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22651</strong></p>
  <p>Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to  the misconfiguration of the Webhook. This component enforces validation  rules and security checks before resources are admitted into the  Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43759 – A Improper Privilege Management vulnerability in SUSE Rancher, allows users with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43759</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43759</strong></p>
  <p>A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43758 – A Improper Neutralization of Special Elements used in an OS Command ('OS Command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43758</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43758</strong></p>
  <p>A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-43757 – A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43757</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-43757</strong></p>
  <p>A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43755 – A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gaine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43755</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43755</strong></p>
  <p>A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31249 – A Improper Neutralization of Special Elements used in an OS Command ('OS Command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31249</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31249</strong></p>
  <p>A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote attackers to inject commands in the underlying host via crafted commands passed to Wrangler. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler version 0.8.4 and prior versions; wrangler version 1.0.0 and prior versi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21953 – A Missing Authorization vulnerability in of SUSE Rancher allows authenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21953</guid>
    <pubDate>Tue, 07 Feb 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21953</strong></p>
  <p>A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31247 – An Improper Authorization vulnerability in SUSE Rancher, allows any user who has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31247</guid>
    <pubDate>Wed, 07 Sep 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31247</strong></p>
  <p>An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36783 – A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36783</guid>
    <pubDate>Wed, 07 Sep 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36783</strong></p>
  <p>A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36782 – A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36782</guid>
    <pubDate>Wed, 07 Sep 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36782</strong></p>
  <p>A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36784 – A Improper Privilege Management vulnerability in SUSE Rancher allows users with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36784</guid>
    <pubDate>Mon, 02 May 2022 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36784</strong></p>
  <p>A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36778 – A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36778</guid>
    <pubDate>Mon, 02 May 2022 12:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36778</strong></p>
  <p>A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36776 – A Improper Access Control vulnerability in SUSE Rancher allows remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36776</guid>
    <pubDate>Mon, 04 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36776</strong></p>
  <p>A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36775 – a Improper Access Control vulnerability in SUSE Rancher allows users to keep pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36775</guid>
    <pubDate>Mon, 04 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36775</strong></p>
  <p>a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21947 – A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21947</guid>
    <pubDate>Fri, 01 Apr 2022 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21947</strong></p>
  <p>A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31999 – A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31999</guid>
    <pubDate>Thu, 15 Jul 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31999</strong></p>
  <p>A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" or "Impersonate-Group" headers. This issue affects: Rancher versions prior to 2.5.9. Rancher versions prior to 2.4.16.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25320 – A Improper Access Control vulnerability in Rancher, allows users in the cluster ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25320</guid>
    <pubDate>Thu, 15 Jul 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25320</strong></p>
  <p>A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25318 – A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25318</guid>
    <pubDate>Thu, 15 Jul 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25318</strong></p>
  <p>A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25313 – A Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25313</guid>
    <pubDate>Fri, 05 Mar 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25313</strong></p>
  <p>A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11202 – An issue was discovered that affects the following versions of Rancher: v2.0.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11202</guid>
    <pubDate>Tue, 30 Jul 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11202</strong></p>
  <p>An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recre…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12303 – In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12303</guid>
    <pubDate>Thu, 06 Jun 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12303</strong></p>
  <p>In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12274 – In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12274</guid>
    <pubDate>Thu, 06 Jun 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12274</strong></p>
  <p>In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6287 – In Rancher 2.0.0 through 2.1.5, project members have continued access to create,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6287</guid>
    <pubDate>Wed, 10 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6287</strong></p>
  <p>In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20321 – An issue was discovered in Rancher 2 through 2.1.5. Any project member with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20321</guid>
    <pubDate>Wed, 10 Apr 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20321</strong></p>
  <p>An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. This could be mitigated by isolating the default namespace in a separate project, where only cluster admins can be given permissions to access.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7297 – Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disablin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7297</guid>
    <pubDate>Wed, 29 Mar 2017 00:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7297</strong></p>
  <p>Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7297">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
