An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 5
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
|
2.15.0
|
2.15.2
|
|
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
|
2.14.0
|
2.14.6
|
|
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
|
2.13.0
|
2.13.10
|
|
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
|
2.12.0
|
2.12.14
|
|
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
|
2.11.0se
|
2.11.18
|