Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xfj7-qf8w-2gcr | Rancher 'Audit Log' leaks sensitive information |
Wed, 30 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse rancher |
|
| CPEs | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:undefined |
|
| Vendors & Products |
Suse
Suse rancher |
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rancher
Rancher rancher |
|
| CPEs | cpe:2.3:a:rancher:rancher:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rancher
Rancher rancher |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 16 Oct 2024 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels) set to `1 or above` are impacted by this issue. | |
| Title | Rancher 'Audit Log' leaks sensitive information | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-10-16T17:26:00.938Z
Reserved: 2023-01-05T10:40:08.605Z
Link: CVE-2023-22649
Updated: 2024-10-16T16:28:57.600Z
Status : Analyzed
Published: 2024-10-16T08:15:04.390
Modified: 2024-10-30T21:08:46.247
Link: CVE-2023-22649
No data.
OpenCVE Enrichment
No data.
Github GHSA