A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43757.json",
"cwe_ids": [
"CWE-312"
],
"cna_assigner": "suse",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "Rancher"
},
{
"fixed": "2.5.17"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "2.5.0"
},
{
"fixed": "2.5.17"
},
{
"introduced": "2.6.0"
},
{
"fixed": "2.6.10"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.1"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*"
}