A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of service by supplying specially crafted git credentials. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler version 0.8.4 and prior versions; wrangler version 1.0.0 and prior versions.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/rancher/wrangler(Go) | 0 | 0.7.4-security1 | N/A |
| github.com/rancher/wrangler(Go) | 0.8.0 | 0.8.5-security1 | N/A |
| github.com/rancher/wrangler(Go) | 1.0.0 | 1.0.1 | N/A |
| github.com/rancher/wrangler(Go) | 0.8.6 | 0.8.11 | N/A |
CVSS Metrics