Rancher vSphere Vulnerability: Plaintext Storage of CPI/CSI Credentials
CVE-2022-45157

9.1CRITICAL

Key Information:

Vendor
Suse
Status
Vendor
CVE Published:
13 November 2024

Summary

A vulnerability has been identified in Rancher's handling of vSphere's Cloud Provider Interface (CPI) and Container Storage Interface (CSI) credentials. This issue arises from the insecure storage of CPI and CSI passwords as plaintext within Rancher. As a result, any deployment of clusters in vSphere environments is susceptible to credential exposure. This vulnerability highlights the critical need for secure credential management practices to safeguard sensitive information in cloud operations, particularly for users leveraging Rancher with vSphere.

Affected Version(s)

rancher 2.9.0 < 2.9.3

rancher 2.7.0 < 2.8.9

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.