CVE-2026-93537: falha de média gravidade em SUSE Rancher
Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.5epss 0.3%
probabilidade de exploração
0.3%top 79% das CVEs
exploração observada
nãonenhuma fonte reporta
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.
This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Produtos afetados
SUSE · RancherCVEs relacionadas — SUSE Rancher
No mesmo produto, das mais perigosas para as menos.
CVE-2021-36782CRITICALRancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectEPSS 4.2%CVE-2022-31249HIGH[RANCHER] OS command injection in Rancher and FleetEPSS 3.8%CVE-2022-43755HIGHRancher: Non-random authentication tokenEPSS 1.7%CVE-2021-25313HIGHRancher: XSS on /v3/cluster/EPSS 1.5%CVE-2026-44939CRITICALCommand injection through unsanitized YAML parameter in RancherEPSS 1.3%CVE-2021-36776HIGHSteve API proxy impersonationEPSS 1.1%