HIGH
Users can issue watch commands for arbitrary resources
Published Apr 11, 2025
7.7
HIGHCVSS 3.1
EPSS 0.47%
Description
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.
Affected products
-
- Version 0StatusaffectedConstraints<2175e09
- Version 0StatusaffectedConstraints<6e30359
- Version 0StatusaffectedConstraints<c744f0b
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/rancher/steve
Go
Introduced 0 Fixed 0.0.0-20241029132712-2175e090fe4b
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rancher/steve | 0 | 0.0.0-20241029132712-2175e090fe4b |
Remediation
No remediation recorded yet.
References (7)
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-52280
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3361 Advisory
- https://github.com/advisories/GHSA-j5hq-5jcr-xwx7 Advisory
- https://github.com/rancher/steve/commit/2175e090fe4b1e603a54e1cdc5148a2b1c11b4d9
- https://github.com/rancher/steve/security/advisories/GHSA-j5hq-5jcr-xwx7
- https://nvd.nist.gov/vuln/detail/CVE-2024-52280
- https://pkg.go.dev/vuln/GO-2024-3281
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Apr 11, 2025
Updated Apr 11, 2025
Reserved Nov 6, 2024
Link CVE-2024-52280
CISA Vulnrichment
Updated Apr 11, 2025
ENISA EUVD
EUVD-2024-3361 GHSA-J5HQ-5JCR-XWX7 Assigner suse
Published Apr 11, 2025
Updated Apr 11, 2025
Exploited since n/a
Link EUVD-2024-3361