We found results for “”
CVE-2024-22032
Good to know:
Date: October 16, 2024
In Rancher 2.7 before 2.7.14 and 2.8 before 2.8.5 RKE1 Secrets Encryption Config secrets in plaintext in cluster AppliedSpec. This could lead to an unauthorized user gaining access to the entire secrets encryption config specific for the cluster, only on the applied spec.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |