Unauthenticated Cross-Site Scripting (XSS) Vulnerability
CVE-2023-32192
8.3HIGH
Summary
A security flaw has been discovered in the Rancher API Server, specifically within the public API endpoint. This vulnerability enables attackers to exploit unauthenticated cross-site scripting (XSS) weaknesses, allowing them to execute arbitrary JavaScript code in the browsers of unsuspecting users. Such an attack vector can lead to various harmful consequences, including data theft, session hijacking, and the delivery of malicious payloads. Mitigating this vulnerability is crucial to safeguard users and maintain the integrity of the API services. For further details, refer to the advisories and discussions available on the respective platforms.
Affected Version(s)
apiserver 0 < 0.0.0-20240207153957-4fd7d821d952
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database