Rancher Labs Rancher是美国Rancher Labs公司的一套开源的企业级容器管理平台。 Rancher 存在授权问题漏洞,该漏洞源于产品对于关键资源的管理缺少有效的权限管理,攻击者可通过该漏洞访问不该访问的资源。以下产品及版本受到影响:Rancher 2.5.9之前版本,Rancher 2.4.16之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-25320 | 9.9 CRITICAL | Rancher: Cloud credentials can be used through proxy API by users without access |
| CVE-2021-31999 | 8.8 HIGH | Rancher: Privilege escalation vulnerability via malicious Connection header |
No comments yet