SUSE Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*
- >= 2.9.0, < 2.9.4
- < 2.10.0
A stored cross-site scripting vulnerability has been identified in SUSE Rancher versions 2.9.0 prior to 2.9.4. This issue allows a malicious actor to inject harmful scripts through the cluster description field, which are then executed when the description is viewed. The vulnerability arises from improper input sanitization during web page generation.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected cluster description.
Users are advised to upgrade to Rancher versions 2.9.4 or 2.10.0, both of which include the necessary fix. The advisory recommends consulting the SUSE Rancher support matrix and product support lifecycle for guidance on version compatibility.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.