CVE-2025-23387
MEDIUMRancher 2.8.0-2.8.12, 2.9.0-2.9.6, 2.10.0-2.10.2 - Unauthenticated Sensitive Info Exposure via CLI
Title source: llmDescription
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
References (2)
Core 2
Core References
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23387
Scores
CVSS v3
5.3
EPSS
0.0018
EPSS Percentile
38.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (4)
rancher/rancher
2.8.0 - 2.8.13Go
SUSE/rancher
2.10.0 - 2.10.3
SUSE/rancher
2.8.0 - 2.8.13
SUSE/rancher
2.9.0 - 2.9.7
Published
Apr 11, 2025
Tracked Since
Feb 18, 2026