CVE-2024-22030: Suse Rancher

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL.

Affected products

  • Suse Rancher: from 2.7.0, before 2.7.15 (fixed in 2.7.15); from 2.8.0, before 2.8.8 (fixed in 2.8.8); from 2.9.0, before 2.9.2 (fixed in 2.9.2)

Published 2024-10-16. Last modified 2026-06-17.