PT-2025-9096 · Rancher · Rancher

Andy Pitcher

·

Published

2025-02-27

·

Updated

2025-04-11

·

CVE-2025-23389

CVSS v3.1

8.4

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Rancher versions 2.8.0 through 2.8.12 Rancher versions 2.9.0 through 2.9.6 Rancher versions 2.10.0 through 2.10.2
Description A vulnerability in Rancher allows local user impersonation through SAML Authentication on first login. The issue occurs when a SAML authentication provider is configured, and a newly created user can impersonate any user on Rancher by manipulating cookie values during their initial login. This vulnerability could also be exploited if a Rancher user is removed. Rancher validates only a subset of input from the SAML assertion request and trusts values that are not properly validated, allowing an attacker to configure the saml Rancher UserID cookie and the saml Rancher Action cookie to add the user principal from the authentication provider to the user specified by the attacker.
Recommendations For versions 2.8.0 through 2.8.12, update to version 2.8.13 or later. For versions 2.9.0 through 2.9.6, update to version 2.9.7 or later. For versions 2.10.0 through 2.10.2, update to version 2.10.3 or later. As a temporary workaround for deployments that cannot upgrade, consider disabling the SAML-based authentication provider to minimize the risk of exploitation.

Fix

Improper Access Control

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-23389
GHSA-MQ23-VVG7-XFM4
GO-2025-3490
OPENSUSE-SU-2025:14889-1

Affected Products

Rancher