PT-2021-19621 · Suse · Suse Rancher K3S+1
Chris Wayne
·
Published
2021-07-28
·
Updated
2022-11-14
·
CVE-2021-32001
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SUSE Rancher K3s versions v1.19.12+k3s1 through v1.21.2+k3s1 and prior versions
RKE2 versions v1.19.12+rke2r1 through v1.21.2+rke2r1 and prior versions
Description:
A Missing Encryption of Sensitive Data issue allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value.
Recommendations:
For SUSE Rancher K3s versions v1.19.12+k3s1 through v1.21.2+k3s1 and prior versions, consider restricting access to the datastore and backups to minimize the risk of exploitation.
For RKE2 versions v1.19.12+rke2r1 through v1.21.2+rke2r1 and prior versions, consider implementing additional security measures to protect the cluster's confidential keying material.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rke2
Suse Rancher K3S