CVE-2024-52281: Suse Rancher

High severity, CVSS 8.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field. This issue affects rancher: from 2.9.0 before 2.9.4.

Affected products

  • Suse Rancher: from 2.9.0, before 2.9.4 (fixed in 2.9.4)

Published 2025-04-16. Last modified 2026-06-17.