CVE-2021-36782: critical vulnerability in SUSE Rancher
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
Published · Updated
Patch soon. It has a working public exploit.
Rancher stores sensitive credentials in plain text where authenticated users can read them through the Kubernetes API. This means anyone with basic access to a Rancher cluster can retrieve passwords and secrets that should be protected.
CWE-312 vulnerability allows authenticated users (Cluster Owners, Members, Project Owners, Members, and base users) to retrieve plaintext sensitive data via Kubernetes API calls in Rancher versions before 2.5.16 and 2.6.7. Pre-conditions require valid authentication; impact includes exposure of all stored credentials and secrets.
In the same product, most dangerous first.