Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SUSE — Vulnerabilities & Security Advisories 214

Browse all 214 CVE security advisories affecting SUSE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SUSE operates primarily as a provider of enterprise Linux distributions and cloud-native solutions, serving critical infrastructure in hybrid and multi-cloud environments. With 185 recorded CVEs, its vulnerability profile reflects the complexity of managing large-scale open-source codebases. Historically, common flaw classes include remote code execution (RCE), buffer overflows, and privilege escalation vulnerabilities, often stemming from misconfigurations or outdated dependencies within its core operating system components. Notable security characteristics involve its focus on container security and Kubernetes integration, which introduces attack surfaces related to orchestration layers. While no single catastrophic incident defines its history, the sheer volume of vulnerabilities highlights the ongoing challenge of maintaining security in widely deployed, long-term support releases. This necessitates rigorous patch management and continuous monitoring to mitigate risks associated with its extensive ecosystem of integrated services and third-party libraries.

Found 67 results / 214 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2024-52281 Stored Cross-site Scripting vulnerability in Rancher UI — rancher CWE-79 8.9 High 2025-04-16
CVE-2024-52280 Users can issue watch commands for arbitrary resources — rancher CWE-200 7.7 High 2025-04-11
CVE-2024-52282 Rancher Helm Applications may have sensitive values leaked — rancher CWE-200 6.2 Medium 2025-04-11
CVE-2025-23387 Rancher's SAML-based login via CLI can be denied by unauthenticated users — rancher CWE-200 5.3 Medium 2025-04-11
CVE-2025-23388 Unauthenticated stack overflow in /v3-public/authproviders API — rancher CWE-121 8.2 High 2025-04-11
CVE-2025-23389 Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login — rancher CWE-284 8.4 High 2025-04-11
CVE-2025-23391 Rancher: Restricted Administrator can change Administrator's passwords — rancher CWE-266 9.1 Critical 2025-04-11
CVE-2022-45157 Exposure of vSphere's CPI and CSI credentials in Rancher — rancher CWE-522 9.1 Critical 2024-11-13
CVE-2024-22032 Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec — rancher CWE-200 6.5 Medium 2024-10-16
CVE-2024-22030 Rancher agents can be hijacked by taking over the Rancher Server URL — rancher CWE-295 8.0 High 2024-10-16
CVE-2023-32196 Rancher's External RoleTemplates can lead to privilege escalation — rancher CWE-269 6.6 Medium 2024-10-16
CVE-2023-32194 Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core' — rancher CWE-269 7.2 High 2024-10-16
CVE-2023-22650 Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider — rancher CWE-287 8.8 High 2024-10-16
CVE-2023-22649 Rancher 'Audit Log' leaks sensitive information — rancher CWE-532 8.4 High 2024-10-16
CVE-2022-43760 Rancher Labs Rancher 跨站脚本漏洞 — Rancher CWE-79 8.4 High 2023-06-01
CVE-2023-22647 Rancher Labs Rancher 安全漏洞 — Rancher CWE-267 9.9 Critical 2023-06-01
CVE-2023-22648 Rancher Labs Rancher 安全漏洞 — Rancher CWE-271 8.0 High 2023-06-01
CVE-2023-22651 Rancher 安全漏洞 — Rancher CWE-269 9.9 Critical 2023-05-04
CVE-2022-43757 Rancher: Exposure of sensitive fields — Rancher CWE-312 9.9 Critical 2023-02-07
CVE-2022-21953 Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster — Rancher CWE-862 7.4 High 2023-02-07
CVE-2022-31249 [RANCHER] OS command injection in Rancher and Fleet — Rancher CWE-78 7.5 High 2023-02-07
CVE-2022-43755 Rancher: Non-random authentication token — Rancher CWE-331 7.1 High 2023-02-07
CVE-2022-43756 Rancher/Wrangler: Denial of service when processing Git credentials — Rancher CWE-74 5.9 Medium 2023-02-07
CVE-2022-43758 Rancher: Command injection in Git package — Rancher CWE-78 7.6 High 2023-02-07
CVE-2022-43759 Rancher: Privilege escalation via promoted roles — Rancher CWE-269 7.2 High 2023-02-07
CVE-2022-31247 Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB) — Rancher CWE-285 9.1 Critical 2022-09-07
CVE-2021-36783 Rancher: Failure to properly sanitize credentials in cluster template answers — Rancher CWE-522 9.9 Critical 2022-09-07
CVE-2021-36782 Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object — Rancher CWE-312 9.9 Critical 2022-09-07
CVE-2022-21951 Rancher: Weave CNI password is not set if RKE template is used with CNI value overridden — Rancher CWE-319 6.8 Medium 2022-05-25
CVE-2021-4200 Write access to the Catalog for any user when restricted-admin role is enabled — Rancher CWE-269 5.4 Medium 2022-05-02

This page lists every published CVE security advisory associated with SUSE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.