CVE-2022-45157 - CVE House
Back to Database
Status published High CVE-2022-45157

Exposure of vSphere's CPI and CSI credentials in Rancher

Vulnerability Description

A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside Rancher. This vulnerability is only applicable to users that deploy clusters in vSphere environments.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45157

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rancher
Vulnerable Versions:
2.9.0, 2.7.0

Timeline

Official Publish: November 13th, 2024
Last Modified: November 13th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Weaknesses (CWE)