Vulnerabilities > CVE-2021-36778 - Incorrect Authorization vulnerability in Suse Rancher

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
suse
CWE-863

Summary

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

Vulnerable Configurations

Part Description Count
Application
Suse
265

Common Weakness Enumeration (CWE)