CVE Tools

Rancher-labs

3 CVEs tracked since 2022. Since Sep 2022, none of them reached CISA KEV.

Rancher-labs CVEs per month

Sep 2022 to Sep 2022. Point at a month, or focus the strip and use the arrow keys.
Rancher-labs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0930

Products

The products that kept showing up in Rancher-labs's monthly top three, with their CVEs summed over those months.

  1. Rancher31 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Rancher-labs.

  1. CVE-2023-32197Rancher's External RoleTemplates can lead to privilege escalation6.6
  2. CVE-2024-52281Stored Cross-site Scripting vulnerability in Rancher UI8.9
  3. CVE-2025-23391Rancher: Restricted Administrator can change Administrator's passwords9.1
  4. CVE-2022-45157Exposure of vSphere's CPI and CSI credentials in Rancher9.1
  5. CVE-2023-32191rke's credentials are stored in the RKE1 Cluster state ConfigMap9.9
  6. CVE-2023-22651Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhoo...9.9
  7. CVE-2022-31247Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)9.1
  8. CVE-2021-36782Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object9.9
  9. CVE-2021-36783Rancher: Failure to properly sanitize credentials in cluster template answers9.9
  10. CVE-2021-31999Rancher: Privilege escalation vulnerability via malicious Connection header8.8
  11. CVE-2021-25318rancher: API group not properly specified when creating Kubernetes RBAC resources8.8

The record

Peak rank
#200 in Sep 2022
Busiest month shown
Sep 2022, 3 CVEs
Months with a KEV entry
0 since Sep 2022
Monthly snapshots
1 since 2022
Rancher-labs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store