Логотип exploitDog
bind:CVE-2024-22032
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-22032

Количество 2

Количество 2

nvd логотип

CVE-2024-22032

больше 1 года назад

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written in plaintext on the AppliedSpec. Cluster owners, Cluster members, and Project members (for projects within the cluster), all have RBAC permissions to view the cluster object from the apiserver.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q6c7-56cq-g2wm

больше 1 года назад

Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-22032

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written in plaintext on the AppliedSpec. Cluster owners, Cluster members, and Project members (for projects within the cluster), all have RBAC permissions to view the cluster object from the apiserver.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-q6c7-56cq-g2wm

Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу