PT-2024-19165 · Rke2+2 · Rke2+2

Jarkko Vesiluoma

·

Published

2024-02-19

·

Updated

2024-11-05

·

CVE-2024-22030

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rancher versions 2.7.0 through 2.7.14 Rancher versions 2.8.0 through 2.8.7 Rancher versions 2.9.0 through 2.9.1
Description A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL. This issue has a high complexity bar, and there is no reported successful exploitation.
Recommendations For Rancher versions 2.7.0 through 2.7.14, upgrade to version 2.7.15 to stay protected. For Rancher versions 2.8.0 through 2.8.7, upgrade to version 2.8.8 to stay protected. For Rancher versions 2.9.0 through 2.9.1, upgrade to version 2.9.2 to stay protected. As a temporary workaround, consider following standard security practices, including properly controlling the expiration and ownership of the domain used as the Rancher URL, enabling DNSSEC, and properly cleaning up and decommissioning unused clusters and downstream clusters. For Windows nodes running older versions of RKE2, manually resolve the issue by following the provided instructions and updating the rancher-wins version to 0.4.18 or greater.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22030
GHSA-H4H5-9833-V2P4
GO-2024-3161
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Rke2
Rancher
Suse