CVE-2021-36782

Scores

EPSS

0.796medium79.6%
0%20%40%60%80%100%

Percentile: 79.6%

CVSS

9.9critical3.x
0246810

CVSS Score: 9.9/10

All CVSS Scores

CVSS 3.x
9.9

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-312

Related Vulnerabilities

Exploits

Exploit ID: CVE-2021-36782

Source: github-poc

URL: https://github.com/fe-ax/tf-cve-2021-36782

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: rancher

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",      "versionEndExcluding": "2.5.16",      "versionStartIncluding": "2.5.0",      "vulnerable": true    },    ...

Source: nvd

End of list