CVE-2022-43755: Rancher: Non-random authentication token
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43755?
CVE-2022-43755 is an Insufficient Entropy vulnerability in SUSE Rancher that allows attackers who have knowledge of the cattle-token to continue abusing it even after the token has been renewed.
Which versions of SUSE Rancher are affected by CVE-2022-43755?
CVE-2022-43755 affects SUSE Rancher versions prior to 2.6.10 and Rancher versions prior to 2.7.1.
How severe is CVE-2022-43755?
CVE-2022-43755 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-43755?
To fix this vulnerability, it is recommended to update your SUSE Rancher installation to versions 2.6.10 or 2.7.1 or later.
Where can I find more information about CVE-2022-43755?
You can find more information about CVE-2022-43755 at the following reference link: [https://bugzilla.suse.com/show_bug.cgi?id=1205297](https://bugzilla.suse.com/show_bug.cgi?id=1205297)