Vulnerabilities > Suse > Rancher

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-11202 Improper Authentication vulnerability in Suse Rancher
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1.
network
low complexity
suse CWE-287
critical
9.8
2019-06-10 CVE-2019-11881 Unspecified vulnerability in Suse Rancher 2.1.4
A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols.
network
low complexity
suse
4.7
2019-06-06 CVE-2019-12303 Injection vulnerability in Suse Rancher
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
network
low complexity
suse CWE-74
8.8
2019-06-06 CVE-2019-12274 Missing Authorization vulnerability in Suse Rancher
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud.
network
low complexity
suse CWE-862
8.8
2019-04-10 CVE-2019-6287 Improper Privilege Management vulnerability in Suse Rancher
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
network
low complexity
suse CWE-269
8.1
2019-04-10 CVE-2018-20321 Exposure of Resource to Wrong Sphere vulnerability in Suse Rancher
An issue was discovered in Rancher 2 through 2.1.5.
network
low complexity
suse CWE-668
8.8
2017-03-29 CVE-2017-7297 Unspecified vulnerability in Suse Rancher
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call.
network
low complexity
suse
8.8