CVE-2022-43758 HIGH

CVE-2022-43758: Rancher: Command injection in Git package

Vendor Suse
Product Rancher
Weakness CWE-78
Published February 7, 2023
Last update March 25, 2025

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

Key dates

02Disclosure timeline

February 7, 2023 CVE published
March 25, 2025 Record updated