Database/Container, Kubernetes & orchestration
Rancher: Insufficient entropy means a leaked cattle-token stays usable after rotation
CVSS 7.1CVE-2022-43755Container, Kubernetes & orchestrationcurated
Impact
Insufficient entropy means a leaked cattle-token stays usable after rotation
Who can reach it
An attacker who once observed the token
What to do
Upgrade Rancher; force full token regeneration
References
Related entries
- Rancher: Cluster owners, members and even base users retrieve plaintext credentials via the Kubernetes APICVE-2021-36782 · RancherCritical
- Rancher: Insufficiently protected credentials let project members read passwords and API tokensCVE-2021-36783 · RancherCritical
- Rancher: Cleartext credential storage lets managed-cluster users read credentialsCVE-2022-43757 · RancherCritical
- Rancher: Standard users manipulate Kubernetes secrets in the local (management) clusterCVE-2023-22647 · RancherCritical
- Rancher: Update-logic failure misconfigures Rancher's admission webhook, disabling the validation that enforcesCVE-2023-22651 · RancherCritical
- Rancher: SAML assertion replay: the ACS handler does not enforce one-time use, so a captured assertion logsCVE-2026-44946 · RancherCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.