Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-23387

Опубликовано: 11 апр. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

EPSS

Процентиль: 47%
0.00238
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
github
12 месяцев назад

Rancher's SAML-based login via CLI can be denied by unauthenticated users

EPSS

Процентиль: 47%
0.00238
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200