Exposure of repository credentials to external third-party sources

CVE-2021-36778
7.3HIGH

Key Information

Vendor
Suse
Status
Rancher
Vendor
CVE Published:
2 May 2022

Summary

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

Affected Version(s)

Rancher < 2.5.12

Rancher < 2.6.3

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: 7.5 to: 7.3 - (HIGH)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Avatar Martin Andreas Ullrich
.