CVE-2022-21947

A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.
References
Link Resource
https://bugzilla.suse.com/show_bug.cgi?id=1197491 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:suse:rancher_desktop:*:*:*:*:*:*:*:*

History

06 Jul 2023, 15:15

Type Values Removed Values Added
Summary A Improper Access Control vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V. A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.

27 Jun 2023, 19:01

Type Values Removed Values Added
CWE CWE-284 CWE-668

11 Apr 2022, 19:16

Type Values Removed Values Added
CPE cpe:2.3:a:suse:rancher_desktop:*:*:*:*:*:*:*:*
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1197491 - (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1197491 - Issue Tracking, Third Party Advisory
First Time Suse rancher Desktop
Suse
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 8.8

01 Apr 2022, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-01 07:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-21947

Mitre link : CVE-2022-21947

CVE.ORG link : CVE-2022-21947


JSON object : View

Products Affected

suse

  • rancher_desktop
CWE
CWE-668

Exposure of Resource to Wrong Sphere