A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Suse Rancher_Backup_And_Restore_Operator
cpe:2.3:a:suse:rancher_backup_and_restore_operator:*:*:*:*:*:*:*:*
|
6.0.0
|
6.0.3
|
|
Suse Rancher_Backup_And_Restore_Operator
cpe:2.3:a:suse:rancher_backup_and_restore_operator:*:*:*:*:*:*:*:*
|
7.0.0
|
7.0.5
|
|
Suse Rancher_Backup_And_Restore_Operator
cpe:2.3:a:suse:rancher_backup_and_restore_operator:*:*:*:*:*:*:*:*
|
8.0.0
|
8.1.2
|
|
Suse Rancher_Backup_And_Restore_Operator
cpe:2.3:a:suse:rancher_backup_and_restore_operator:*:*:*:*:*:*:*:*
|
9.0.0
|
9.0.1
|