CVE-2022-21947
Summary
| CVE | CVE-2022-21947 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-01 07:15:00 UTC |
| Updated | 2023-07-06 15:15:00 UTC |
| Description | A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Suse | Rancher Desktop | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1197491 – VUL-0: CVE-2022-21947: rancher desktop: Dashboard API is network accessible | CONFIRM | bugzilla.suse.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.