PT-2025-39666 · Suse · Rancher Manager

Samjustus

·

Publicado

2025-09-26

·

Atualizado

2025-10-27

·

CVE-2025-54468

CVSS v3.1

4.7

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rancher Manager versions prior to 2.9.12 Rancher Manager versions prior to 2.10.10 Rancher Manager versions prior to 2.11.6 Rancher Manager versions prior to 2.12.2
Description A flaw exists in Rancher Manager that allows sensitive information, such as email addresses, to be sent in Impersonate-Extra-* headers to external entities when creating new cloud credentials. This occurs via the /meta/proxy API endpoint. The information is sent to whitelisted domains specified in nodedrivers.management.cattle.io objects, including domains like amazonaws.com and api.digitalocean.com. The headers involved include Impersonate-Extra-Username and Impersonate-Extra-Principalid. Passwords, password hashes, and Rancher authentication tokens are not leaked.
Recommendations Update Rancher Manager to version 2.9.12 or later. Update Rancher Manager to version 2.10.10 or later. Update Rancher Manager to version 2.11.6 or later. Update Rancher Manager to version 2.12.2 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-54468
GHSA-MJCP-RJ3C-36FR
GO-2025-3982
OPENSUSE-SU-2025:15666-1
SUSE-SU-2025:3799-1

Produtos afetados

Rancher Manager