4.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Description
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.
Basic Information
ID
CVE-2025-54468
Source
suse
Published
Oct 2, 2025 at 10:00
Affected Product
Vendor
SUSE
Product
rancher
Version
2.12.0
Affected Versions
SUSE rancher 2.12.0
SUSE rancher 2.11.0
SUSE rancher 2.10.0
SUSE rancher 2.9.0
SUSE rancher 2.11.0
SUSE rancher 2.10.0
SUSE rancher 2.9.0