PT-2019-12727 · Rancher · Rancher

Published

2019-06-06

·

Updated

2024-08-20

·

CVE-2019-12274

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rancher versions 1 through 2.2.3 Rancher versions 2 through 2.2.3
Description The issue allows unprivileged users to gain admin access to the Rancher management plane by posting sensitive data to the cloud. This can be achieved by exploiting node driver options that permit posting certain files. Additionally, project owners can inject extra fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
Recommendations For Rancher versions 1 through 2.2.3, consider restricting access to node deployment features for unprivileged users until a patch is available. For Rancher versions 2 through 2.2.3, restrict project owners' ability to inject additional fluentd configuration to prevent code injection and arbitrary command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Missing Authorization

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2019-12274
GHSA-53PJ-67M4-9W98
GHSA-GC62-J469-9GJM
GO-2023-1991
GO-2024-2762

Affected Products

Rancher