Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mauro Eldritch

#50399de 53,635
4.7CVSS total
Vulnerabilidades · 1
PT-2019-12541
4.7
2019-06-10
Rancher · Rancher · CVE-2019-11881
**Name of the Vulnerable Software and Affected Versions** Rancher versions prior to 2.2.4 Rancher version 2.1.4 **Description** A vulnerability exists in the login component of Rancher, where the `errorMsg` parameter can be tampered to display arbitrary content. Although tags are filtered, special characters and symbols are not, allowing malicious users to lure legitimate users to visit phishing sites using scare tactics. For example, a message can be displayed stating "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading". **Recommendations** For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. For version 2.1.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the login component to minimize the risk of exploitation. Avoid using the `errorMsg` parameter in the login endpoint until the issue is resolved.