← Back

CVE-2022-43758

nvd nist
Published: Feb 7, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

Affected (3)

Products: Suse: Rancher
1 product
Rancher
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Suse
From 2.5.0 to 2.5.17
From 2.6.0 to 2.6.10
From 2.7.0 to 2.7.1

References (2)

Source: meissner@suse.de
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.