CVE-2024-52284: Suse Rancher

High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

Affected products

  • Suse Rancher: from 0.13.0, before 0.13.1-0.20250806151509-088bcbea7edb (fixed in 0.13.1-0.20250806151509-088bcbea7edb); from 0.12.0, before 0.12.6 (fixed in 0.12.6); from 0.11.0, before 0.11.10 (fixed in 0.11.10)

Published 2025-09-02. Last modified 2026-06-17.