CVE-2023-32193: Rancher Norman

High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.

Affected products

  • Rancher Norman: before 0.0.0-20240207153100-3bb70b772b52 (fixed in 0.0.0-20240207153100-3bb70b772b52)
  • Suse Norman: before 0.0.0-20240207153100-3bb70b772b52 (fixed in 0.0.0-20240207153100-3bb70b772b52)

Published 2024-10-16. Last modified 2026-06-17.