This issue affects rancher: from 2.9.0 before 2.9.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0078 | A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4. |
Github GHSA |
GHSA-2v2w-8v8c-wcm9 | Rancher UI has Stored Cross-site Scripting vulnerability |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Apr 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4. | |
| Title | Stored Cross-site Scripting vulnerability in Rancher UI | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-26T18:28:14.954Z
Reserved: 2024-11-06T12:19:57.723Z
Link: CVE-2024-52281
Updated: 2025-04-16T14:22:54.937Z
Status : Deferred
Published: 2025-04-16T09:15:27.620
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52281
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:20Z
EUVD
Github GHSA