<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 20:54:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-173008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173008</link>
      <description>EUVD-2026-173008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173008</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21951</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21951</link>
      <description>&lt;p&gt;A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden This issue affects: SUSE Rancher Rancher versions prior to 2.5.14; Rancher versions prior to 2.6.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden This issue affects: SUSE Rancher Rancher versions prior to 2.5.14; Rancher versions prior to 2.6.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21951</guid>
    </item>
    <item>
      <title>GHSA-vrph-m5jj-c46c — Rancher's weave CNI password is not configured when a cluster is created from an RKE template</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vrph-m5jj-c46c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability only affects customers using [Weave](https://rancher.com/docs/rancher/v2.6/en/faq/networking/cni-providers/#weave) CNI (Container Network Interface) when configured through [RKE templates](https://rancher.com/docs/rancher/v2.6/en/admin-settings/rke-templates/).&lt;/p&gt;
&lt;p&gt;A flaw was discovered in Rancher versions from 2.5.0 up to and including 2.5.13 and from 2.6.0 up to and including 2.6.4, where a UI (user interface) issue with RKE templates does not include a value for the Weave password when Weave is chosen as the CNI.&lt;/p&gt;
&lt;p&gt;If a cluster is created based on the mentioned template and Weave is configured as the CNI, no password will be created for [network encryption](https://www.weave.works/docs/net/latest/tasks/manage/security-untrusted-networks/) in Weave, therefore network traffic in the cluster will be sent unencrypted.&lt;/p&gt;
&lt;p&gt;This issue does not happen when a cluster, with Weave configured as CNI, is created without using an RKE template.&lt;/p&gt;
&lt;p&gt;The impact of this vulnerability is higher when nodes on the cluster are on different locations and communicate with one another through the Internet, where monitoring (sniffing) of the network traffic by third-party entities can be more easily achieved.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions include releases 2.5.14, 2.6.5 and later versions of Rancher. Besides upgrading to a Rancher patched version, the workarounds listed below must be applied in order for Weave to properly encrypt the network traffic.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. A ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability only affects customers using [Weave](https://rancher.com/docs/rancher/v2.6/en/faq/networking/cni-providers/#weave) CNI (Container Network Interface) when configured through [RKE templates](https://rancher.com/docs/rancher/v2.6/en/admin-settings/rke-templates/).&lt;/p&gt;
&lt;p&gt;A flaw was discovered in Rancher versions from 2.5.0 up to and including 2.5.13 and from 2.6.0 up to and including 2.6.4, where a UI (user interface) issue with RKE templates does not include a value for the Weave password when Weave is chosen as the CNI.&lt;/p&gt;
&lt;p&gt;If a cluster is created based on the mentioned template and Weave is configured as the CNI, no password will be created for [network encryption](https://www.weave.works/docs/net/latest/tasks/manage/security-untrusted-networks/) in Weave, therefore network traffic in the cluster will be sent unencrypted.&lt;/p&gt;
&lt;p&gt;This issue does not happen when a cluster, with Weave configured as CNI, is created without using an RKE template.&lt;/p&gt;
&lt;p&gt;The impact of this vulnerability is higher when nodes on the cluster are on different locations and communicate with one another through the Internet, where monitoring (sniffing) of the network traffic by third-party entities can be more easily achieved.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions include releases 2.5.14, 2.6.5 and later versions of Rancher. Besides upgrading to a Rancher patched version, the workarounds listed below must be applied in order for Weave to properly encrypt the network traffic.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. A ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vrph-m5jj-c46c</guid>
    </item>
    <item>
      <title>gsd-2022-21951</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21951</link>
      <description>gsd-2022-21951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21951</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0258 — Rancher: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0258</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in Rancher ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in Rancher ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0258</guid>
    </item>
  </channel>
</rss>
