CVE-2023-22649 Information
Nov 01, 2024
cve
Description
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher’s audit logs. Rancher Audit Logging is an opt-in feature only deployments that have it enabled and have AUDIT_LEVEL set to 1 or above are impacted by this issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22649 https://github.com/rancher/rancher/security/advisories/GHSA-xfj7-qf8w-2gcr
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: