Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhg2-rvm8-w2jh

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

Rancher Vulnerable to Cross-site Request Forgery (CSRF)

Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.

Пакеты

Наименование

github.com/rancher/rancher

go
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.16

2.0.16

Наименование

github.com/rancher/rancher

go
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.11

2.1.11

Наименование

github.com/rancher/rancher

go
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.5

2.2.5

EPSS

Процентиль: 46%
0.00236
Низкий

8.7 High

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.

EPSS

Процентиль: 46%
0.00236
Низкий

8.7 High

CVSS3

Дефекты

CWE-352
CWE-79