
We found results for “”
CVE-2024-22032
Date: October 16, 2024
In Rancher 2.7 before 2.7.14 and 2.8 before 2.8.5 RKE1 Secrets Encryption Config secrets in plaintext in cluster AppliedSpec. This could lead to an unauthorized user gaining access to the entire secrets encryption config specific for the cluster, only on the applied spec.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |