CVE-2025-23387

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-23387
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23387.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-23387
Aliases
Published
2025-04-11T11:15:42Z
Modified
2025-04-12T03:11:39.450263Z
Summary
[none]
Details

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

References

Affected packages

Git / github.com/rancher/rancher

Affected ranges

Type
GIT
Repo
https://github.com/rancher/rancher
Events

Affected versions

v2.*

v2.8.0
v2.8.0-rc5
v2.8.10
v2.8.10-alpha1
v2.8.10-alpha2
v2.8.10-rc1
v2.8.10-rc2
v2.8.11
v2.8.11-alpha1
v2.8.11-rc1
v2.8.12
v2.8.12-alpha1
v2.8.12-alpha2
v2.8.12-rc1
v2.8.13-alpha1
v2.8.13-rc1
v2.8.3
v2.8.3-alpha1
v2.8.3-alpha2
v2.8.3-rc1
v2.8.3-rc2
v2.8.3-rc3
v2.8.3-rc4
v2.8.3-rc5
v2.8.3-rc6
v2.8.3-rc7
v2.8.3-rc8
v2.8.4
v2.8.4-alpha1
v2.8.4-rc1
v2.8.4-rc2
v2.8.4-rc3
v2.8.4-rc4
v2.8.4-rc5
v2.8.6
v2.8.6-alpha1
v2.8.6-alpha2
v2.8.6-alpha3
v2.8.6-alpha4
v2.8.6-alpha5
v2.8.6-alpha6
v2.8.6-rc1
v2.8.6-rc2
v2.8.6-rc3
v2.8.6-rc4
v2.8.7
v2.8.7-rc1
v2.8.7-rc10
v2.8.7-rc2
v2.8.7-rc3
v2.8.7-rc4
v2.8.7-rc5
v2.8.7-rc6
v2.8.7-rc7
v2.8.7-rc8
v2.8.7-rc9
v2.8.8
v2.8.8-alpha1
v2.8.8-alpha2
v2.8.8-rc1
v2.8.9
v2.8.9-alpha1
v2.8.9-alpha10
v2.8.9-alpha2
v2.8.9-alpha3
v2.8.9-alpha4
v2.8.9-alpha5
v2.8.9-alpha6
v2.8.9-alpha8
v2.8.9-alpha9
v2.8.9-rc1
v2.8.9-rc2