Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-44937 Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before … Rancher Fleet 0.12.15 / 0.13.11+ Fix from $1,9502026-07-06 MEDIUM 5.0 CVE-2026-44936 Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b… Rancher Fleet 0.12.15 / 0.13.11+ Fix from $1,6002026-07-06 CRITICAL 9.9 CVE-2026-44935 Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and … Rancher Fleet 0.12.15 / 0.13.11+ Fix from $2,3002026-07-02 HIGH 7.4 CVE-2026-44946 A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, po… Rancher 2.11.15 / 2.12.11+ Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-41053 Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access … Rancher 2.13.6 / 2.14.2+ Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-41052 Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 befor… Rancher 2.12.10 / 2.13.6+ Fix from $1,9502026-06-29 HIGH 8.7 CVE-2026-44543 Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with perm… Local Path Provisioner 0.0.36+ Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-25702 A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via… Linux Enterprise Server Mitigation only Fix from $2,3002026-03-05 HIGH 7.8 CVE-2025-6018 A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw all… Pam Config No fix yet Fix from $1,9502025-07-23 MEDIUM 6.5 CVE-2023-22649 A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://rancherm… Rancher 2.6.14 / 2.7.10+ Fix from $1,6002024-10-16 HIGH 8.8 CVE-2020-10676 In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace t… Rancher 2.6.13 / 2.7.4+ Fix from $1,9502023-12-12 MEDIUM 5.5 CVE-2023-22644 A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perf… Manager Server 4.2.50-150300.3.66.5 / 4.3.58-150400.3.46.4+ Fix from $1,6002023-09-20 HIGH 7.5 CVE-2023-32186 A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor p… Rancher Rke2 1.24.17 / 1.25.13+ Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-22648 A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logg… Rancher 2.6.13 / 2.7.4+ Fix from $1,9502023-06-01 HIGH 8.4 CVE-2022-43760 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-pri… Rancher 2.6.13 / 2.7.4+ Fix from $1,9502023-06-01 HIGH 8.0 CVE-2023-22647 An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes… Rancher 2.6.13 / 2.7.4+ Fix from $1,9502023-06-01 CRITICAL 9.9 CVE-2023-22651 Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook… Rancher after 2.7.2 Fix from $2,3002023-05-04 MEDIUM 5.5 CVE-2022-45155 An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the ca… Opensuse Factory 0.6.1+ Fix from $1,6002023-03-15 HIGH 7.8 CVE-2022-45153 An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En… Linux Enterprise Module For Sap Applications No fix yet Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2022-31249 A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote … Wrangler 0.7.4 / 0.8.5+ Fix from $2,3002023-02-07 CRITICAL 9.8 CVE-2022-43755 A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after t… Rancher 2.6.10 / 2.7.1+ Fix from $2,3002023-02-07 HIGH 8.8 CVE-2022-21953 A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the loca… Rancher 2.5.17 / 2.6.10+ Fix from $1,9502023-02-07 HIGH 8.8 CVE-2022-43757 A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact… Rancher 2.5.17 / 2.6.10+ Fix from $1,9502023-02-07 HIGH 8.8 CVE-2022-43759 A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any… Rancher 2.5.17 / 2.6.10+ Fix from $1,9502023-02-07 HIGH 7.5 CVE-2022-43756 A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote atta… Wrangler 0.7.4 / 0.8.5+ Fix from $1,9502023-02-07 MEDIUM 6.8 CVE-2022-43758 A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for … Rancher 2.5.17 / 2.6.10+ Fix from $1,6002023-02-07 MEDIUM 5.4 CVE-2022-43754 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Mod… Manager Server 4.2.10 / 4.3.2+ Fix from $1,6002022-11-10 CRITICAL 9.9 CVE-2021-36782 A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Proj… Rancher 2.5.16 / 2.6.7+ Fix from $2,3002022-09-07 CRITICAL 9.9 CVE-2021-36783 A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project… Rancher 2.5.13 / 2.6.4+ Fix from $2,3002022-09-07 CRITICAL 9.1 CVE-2022-31247 An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project… Rancher 2.5.16 / 2.6.7+ Fix from $2,3002022-09-07