Rancher cattle-token is predictable

### Impact An issue was discovered in Rancher versions up to and including 2.6.9 and 2.7.0, where the `cattle-token` secret, used by the `cattle-cluster-agent`, is predictable. Even after the token is ...

Continue Reading
Privilege escalation in project role template binding (PRTB) and -promoted roles

### Impact An issue was discovered in Rancher versions from 2.5.0 up to and including 2.5.16 and from 2.6.0 up to and including 2.6.9, where an authorization logic flaw allows privilege escalation via ...

Continue Reading
Privilege escalation in project role template binding (PRTB) and -promoted roles

### Impact An issue was discovered in Rancher versions from 2.5.0 up to and including 2.5.16 and from 2.6.0 up to and including 2.6.9, where an authorization logic flaw allows privilege escalation via ...

Continue Reading
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster

### Impact An issue was discovered in Rancher where an authorization logic flaw allows an authenticated user on any downstream cluster to (1) open a shell pod in the Rancher `local` cluster and (2) ha ...

Continue Reading
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster

### Impact An issue was discovered in Rancher where an authorization logic flaw allows an authenticated user on any downstream cluster to (1) open a shell pod in the Rancher `local` cluster and (2) ha ...

Continue Reading
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects

### Impact This issue affects Rancher versions from 2.5.0 up to and including 2.5.16, from 2.6.0 up to and including 2.6.9 and 2.7.0. It was discovered that the security advisory CVE-2021-36782 (GHSA- ...

Continue Reading
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects

### Impact This issue affects Rancher versions from 2.5.0 up to and including 2.5.16, from 2.6.0 up to and including 2.6.9 and 2.7.0. It was discovered that the security advisory CVE-2021-36782 (GHSA- ...

Continue Reading

CVSS3 - CRITICAL

Rancher generated tokens not revoked after modifications made to authentication provider

### Impact This issue affects Rancher versions from 2.5.0 up to and including 2.5.16, from 2.6.0 up to and including 2.6.9 and 2.7.0. It only affects Rancher setups that have an external [authenticati ...

Continue Reading

Back to Main

Subscribe for the latest news: