Back

HIGH

Users can issue watch commands for arbitrary resources

Published Apr 11, 2025

Description

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before 6e30359, before c744f0b.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Apr 11, 2025
Updated Apr 11, 2025
Reserved Nov 6, 2024
CISA Vulnrichment
Updated Apr 11, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner suse
Published Apr 11, 2025
Updated Apr 11, 2025
Exploited since n/a
EUVD-2024-3361 GHSA-J5HQ-5JCR-XWX7