CVE-2024-52281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/04/2025
Last modified:
15/04/2026

Description

A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field.<br /> This issue affects rancher: from 2.9.0 before 2.9.4.