CVE-2024-52281
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/04/2025
Last modified:
15/04/2026
Description
A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field.<br />
This issue affects rancher: from 2.9.0 before 2.9.4.
Impact
Base Score 3.x
8.90
Severity 3.x
HIGH



