Vulnerabilities > Suse > Rancher > 1.6.26

DATE CVE VULNERABILITY TITLE RISK
2022-05-02 CVE-2021-36778 Incorrect Authorization vulnerability in Suse Rancher
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers.
network
low complexity
suse CWE-863
7.5
2022-05-02 CVE-2021-36784 Improper Privilege Management vulnerability in Suse Rancher
A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin.
network
low complexity
suse CWE-269
6.5
2022-05-02 CVE-2021-4200 Improper Privilege Management vulnerability in Suse Rancher
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled.
network
low complexity
suse CWE-269
5.4
2021-03-05 CVE-2021-25313 Cross-site Scripting vulnerability in Suse Rancher
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links.
network
suse CWE-79
4.3
2019-06-06 CVE-2019-12274 Missing Authorization vulnerability in Suse Rancher
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud.
network
low complexity
suse CWE-862
4.0