Skip to main content

Insufficient Entropy

CVE-2022-43755

Severity High
Score 9.8/10

Summary

A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects SUSE Rancher Rancher versions 2.6.x prior to 2.6.10-rc1, and 2.7.x prior to 2.7.1-rc1.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-331 - Insufficient Entropy

The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Advisory Timeline

  • Published