Skip to main content

Insufficiently Protected Credentials


Severity High
Score 8.8/10


A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated "Cluster Owners", "Cluster Members", "Project Owners" and "Project Members" to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects SUSE Rancher Rancher versions 2.5.x prior to 2.5.13 and 2.6.x prior to 2.6.4.

  • LOW
  • HIGH
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-522 - Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Advisory Timeline

  • Published