Unauthenticated Cross-Site Scripting (XSS) Vulnerability
CVE-2023-32192

8.3HIGH

Key Information:

Vendor
Suse
Status
Apiserver
Vendor
CVE Published:
16 October 2024

Summary

A security flaw has been discovered in the Rancher API Server, specifically within the public API endpoint. This vulnerability enables attackers to exploit unauthenticated cross-site scripting (XSS) weaknesses, allowing them to execute arbitrary JavaScript code in the browsers of unsuspecting users. Such an attack vector can lead to various harmful consequences, including data theft, session hijacking, and the delivery of malicious payloads. Mitigating this vulnerability is crucial to safeguard users and maintain the integrity of the API services. For further details, refer to the advisories and discussions available on the respective platforms.

Affected Version(s)

apiserver 0 < 0.0.0-20240207153957-4fd7d821d952

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.