PT-2022-15200 · Suse · Suse Rancher
Maxsokolovsky
·
Published
2022-05-25
·
Updated
2026-03-03
·
CVE-2022-21951
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Rancher versions prior to 2.5.14
SUSE Rancher versions prior to 2.6.5
Description
A Cleartext Transmission of Sensitive Information issue in SUSE Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden.
Recommendations
For versions prior to 2.5.14, update to version 2.5.14 or later.
For versions prior to 2.6.5, update to version 2.6.5 or later.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Rancher