CVE-2024-52281
HIGHRancher 2.9.0-2.9.3 - Stored Cross-Site Scripting via Cluster Description Field
Title source: llmDescription
A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.
References (2)
Core 2
Core References
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-52281
Scores
CVSS v3
8.9
EPSS
0.0001
EPSS Percentile
1.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (2)
rancher/rancher
2.9.0 - 2.9.4Go
SUSE/rancher
2.9.0 - 2.9.4
Published
Apr 16, 2025
Tracked Since
Feb 18, 2026