Home » Database

AVID-2026-R0823

Description

Exposure of repository credentials to external third-party sources (CVE-2021-36778)

Details

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

Reason for inclusion in AVID: The CVE describes incorrect authorization in SUSE Rancher that exposes repository credentials to third-party sources. While not AI-specific, Rancher is widely used to deploy and manage AI workloads (Kubernetes clusters, CI/CD, container registries). Exposure of credentials used in software supply chains can enable attackers to access or tamper with AI deployment artifacts, making this a relevant software supply-chain vulnerability impacting AI systems. The report provides explicit CVE details, affected versions, CVSS metrics, and references, giving sufficient signal for AVID curation.

References

Affected or Relevant Artifacts

  • Developer: SUSE
  • Deployer: SUSE
  • Artifact Details:
TypeName
SystemRancher
SystemRancher

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score7.3
Base Severity🔴 High
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🟢 Low
Integrity Impact🟢 Low
Availability Impact🟢 Low

CWE

IDDescription
CWE-863CWE-863: Incorrect Authorization

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-05-02
  • Version: 0.3.3
  • AVID Entry