CVE-2021-36778: Exposure of repository credentials to external third-party sources
Published May 2, 2022
·Updated
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.
Affected Software
2 affected components
SUSE rancher<2.5.12
SUSE rancher>=2.6.0<2.6.3
Event History
May 2, 2022
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this SUSE Rancher vulnerability?
The vulnerability ID is CVE-2021-36778.
2
What is the severity of CVE-2021-36778?
The severity of CVE-2021-36778 is high (7.5).
3
Which versions of SUSE Rancher are affected by CVE-2021-36778?
Versions prior to 2.5.12 and versions prior to 2.6.3 of SUSE Rancher are affected by CVE-2021-36778.
4
What is the impact of CVE-2021-36778?
CVE-2021-36778 allows administrators of third-party repositories to gather credentials that are sent to their servers.
5
Is there a fix available for CVE-2021-36778?
Yes, updating to version 2.5.12 or later for Rancher and version 2.6.3 or later for Rancher 2.6 is the recommended fix for CVE-2021-36778.