CVE-2025-54468
EUVD-2025-3133702.10.2025, 10:15
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| suse | rancher | 2.12.0 ≤ 𝑥 < 2.12.2 | CNA |
| suse | rancher | 2.11.0 ≤ 𝑥 < 2.11.6 | CNA |
| suse | rancher | 2.10.0 ≤ 𝑥 < 2.10.10 | CNA |
| suse | rancher | 2.9.0 ≤ 𝑥 < 2.9.12 | CNA |
Common Weakness Enumeration