Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39075
HistoryFeb 02, 2023 - 3:04 a.m.

Information Disclosure

2023-02-0203:04:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
vulnerability
plaintext information
kubernetes clusters
authenticated users
sensitive information
endpoints
software

0.001 Low

EPSS

Percentile

31.0%

github.com/rancher/rancher is vulnerable to Information Disclosure. The vulnerability exists because the library stores sensitive plaintext information directly on Kubernetes Cluster objects , which allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to gain sensitive information through the /v1/management.cattle.io.cluster and /v1/management.cattle.io.clustertemplaterevisions endpoints.

0.001 Low

EPSS

Percentile

31.0%