PT-2022-4712 · Suse · Suse Rancher

Rmweir

·

Published

2022-09-07

·

Updated

2026-03-03

·

CVE-2021-36783

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Rancher versions prior to 2.6.4 Rancher versions prior to 2.5.13
Description A vulnerability in SUSE Rancher allows authenticated users, including Cluster Owners, Cluster Members, Project Owners, and Project Members, to read credentials, passwords, and API tokens stored in cleartext and exposed via API endpoints. This issue is related to the storage of passwords in an unencrypted form, which can be exploited by a remote attacker to gain access to account credentials, passwords, and API tokens.
Recommendations For SUSE Rancher versions prior to 2.6.4, update to version 2.6.4 or later to resolve the issue. For Rancher versions prior to 2.5.13, update to version 2.5.13 or later to resolve the issue. As a temporary workaround, consider restricting access to API endpoints that expose sensitive information until a patch is available.

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-05603
CVE-2021-36783
GHSA-8W87-58W6-HFV8

Affected Products

Suse Rancher