CVE-2021-36782
9.9
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.17% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-312 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-09-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| suse | rancher |
References
→ the Explorer · watch your stack · NVD