Miggo Logo

CVE-2023-22649: Rancher 'Audit Log' leaks sensitive information

7.8

CVSS Score
3.1

Basic Information

EPSS Score
0.96579%
Published
2/8/2024
Updated
10/16/2024
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/rancher/ranchergo>= 2.6.0, < 2.6.142.6.14
github.com/rancher/ranchergo>= 2.7.0, < 2.7.102.7.10
github.com/rancher/ranchergo>= 2.8.0, < 2.8.22.8.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t * vuln*r**ility **s ***n i**nti*i** w*i** m*y l*** to s*nsitiv* **t* **in* l**k** into R*n***r's *u*it lo*s. [R*n***r *u*it Lo**in*](*ttps://r*n***rm*n***r.*o*s.r*n***r.*om/*ow-to-*ui**s/**v*n***-us*r-*ui**s/*n**l*-*pi-*u*it-lo*) is *n op

Reasoning

No *n*lysis *v*il**l*