Upstream information
Description
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type.This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.
SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
CNA (SUSE) | |
---|---|
Base Score | 7.7 |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | Low |
User Interaction | None |
Scope | Changed |
Confidentiality Impact | High |
Integrity Impact | None |
Availability Impact | None |
CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- openSUSE-SU-2024:14519-1, published Mon Nov 25 18:50:12 2024
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2024-14519 |
SUSE Timeline for this CVE
CVE page created: Thu Nov 7 18:30:12 2024CVE page last modified: Fri Apr 11 17:59:32 2025