← Retour aux CVEs
CVE-2022-43758
HIGH7.6
Description
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
Details CVE
Score CVSS v3.17.6
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisHIGH
Interaction utilisateurREQUIRED
Publie2/7/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
suse:rancher
Faiblesses (CWE)
CWE-78
References
https://bugzilla.suse.com/show_bug.cgi?id=1205294(meissner@suse.de)
https://bugzilla.suse.com/show_bug.cgi?id=1205294(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.