CVE-2024-52282 MEDIUM

CVE-2024-52282: Rancher Helm Applications may have sensitive values leaked

Vendor Suse
Product rancher
Weakness CWE-200 · Info exposure
Published April 11, 2025
Last update April 11, 2025

CVSS base score

6.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information leaks into auditing logs when the audit level is set to equal or above 2. This issue affects rancher: from 2.8.0 before 2.8.10, from 2.9.0 before 2.9.4.

Key dates

02Disclosure timeline

April 11, 2025 CVE published
April 11, 2025 Record updated