Vulnerability Name: | CVE-2019-12274 (CCN-162246) | ||||||||||||
Assigned: | 2019-06-05 | ||||||||||||
Published: | 2019-06-05 | ||||||||||||
Updated: | 2022-04-13 | ||||||||||||
Summary: | In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-668 CWE-862 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-12274 Source: XF Type: UNKNOWN rancher-cve201912274-priv-esc(162246) Source: CONFIRM Type: Release Notes, Vendor Advisory https://forums.rancher.com/c/announcements Source: CCN Type: Rancher Web site Rancher Release - v2.2.4 - Addresses Rancher CVE-2019-12274 and CVE-2019-12303 Source: CONFIRM Type: Release Notes, Vendor Advisory https://forums.rancher.com/t/rancher-release-v2-2-4-addresses-rancher-cve-2019-12274-and-cve-2019-12303/14466 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |