CVE-2024-52282
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
11/04/2025
Last modified:
11/04/2025
Description
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET<br />
access to the Rancher Manager Apps Catalog to read any sensitive information that are <br />
contained within the Apps’ values. Additionally, the same information <br />
leaks into auditing logs when the audit level is set to equal or above <br />
2.<br />
<br />
This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.
Impact
Base Score 3.x
6.20
Severity 3.x
MEDIUM



