Miggo Logo

CVE-2022-43757: Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.24102%
Published
1/25/2023
Updated
2/15/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/rancher/ranchergo>= 2.5.0, < 2.5.172.5.17
github.com/rancher/ranchergo>= 2.6.0, < 2.6.102.6.10
github.com/rancher/ranchergo>= 2.7.0, < 2.7.12.7.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t T*is issu* *****ts R*n***r v*rsions *rom *.*.* up to *n* in*lu*in* *.*.**, *rom *.*.* up to *n* in*lu*in* *.*.* *n* *.*.*. It w*s *is*ov*r** t**t t** s**urity **visory *V*-****-***** (**S*-**j*-**q*-*w**), pr*viously r*l**s** *y R*n***r,

Reasoning

No *n*lysis *v*il**l*