A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET
access to the Rancher Manager Apps Catalog to read any sensitive information that are
contained within the Apps’ values. Additionally, the same information
leaks into auditing logs when the audit level is set to equal or above
2.
This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Apr 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information leaks into auditing logs when the audit level is set to equal or above 2. This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4. | |
Title | Rancher Helm Applications may have sensitive values leaked | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-04-11T13:24:10.230Z
Reserved: 2024-11-06T12:19:57.723Z
Link: CVE-2024-52282

Updated: 2025-04-11T13:24:02.823Z

Status : Awaiting Analysis
Published: 2025-04-11T11:15:41.630
Modified: 2025-04-11T15:39:52.920
Link: CVE-2024-52282

No data.