Insufficiently Protected Credentials
CVE-2021-36783
Summary
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated "Cluster Owners", "Cluster Members", "Project Owners" and "Project Members" to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects SUSE Rancher Rancher versions 2.5.x prior to 2.5.13 and 2.6.x prior to 2.6.4.
- LOW
- NETWORK
- HIGH
- CHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-522 - Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References
Advisory Timeline
- Published