PT-2019-10045 · Rancher · Rancher

·

CVE-2018-20321

·

Published

2019-04-10

·

Updated

2024-08-21

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Rancher versions 2.0.0 through 2.1.5
Description: An issue allows project members with access to the default namespace to execute administrative privileged commands against the k8s cluster by mounting the netes-default service account in a pod. This could be mitigated by isolating the default namespace in a separate project, where only cluster admins can be given permissions to access. The issue affects all clusters created or imported by Rancher as of 2018-12-20. Additionally, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
Recommendations: For Rancher versions 2.0.0 through 2.1.5, consider isolating the default namespace in a separate project, where only cluster admins can be given permissions to access, as a temporary workaround to mitigate the risk of exploitation. Restrict access to the netes-default service account to minimize the risk of administrative privileged commands being executed against the k8s cluster. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Improper Privilege Management

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20321
GHSA-6R7X-4Q7G-H83J
GHSA-9QQ2-XHMC-H9QR
GO-2022-0644
GO-2024-2764

Affected Products

Rancher