PT-2019-12727 · Rancher · Rancher
Published
2019-06-06
·
Updated
2024-08-20
·
CVE-2019-12274
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rancher versions 1 through 2.2.3
Rancher versions 2 through 2.2.3
Description
The issue allows unprivileged users to gain admin access to the Rancher management plane by posting sensitive data to the cloud. This can be achieved by exploiting node driver options that permit posting certain files. Additionally, project owners can inject extra fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
Recommendations
For Rancher versions 1 through 2.2.3, consider restricting access to node deployment features for unprivileged users until a patch is available.
For Rancher versions 2 through 2.2.3, restrict project owners' ability to inject additional fluentd configuration to prevent code injection and arbitrary command execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Missing Authorization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rancher