漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Rancher CLI skips TLS verification on Rancher CLI login command
Vulnerability Description
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
证书验证不恰当
Vulnerability Title
SUSE Rancher 信任管理问题漏洞
Vulnerability Description
SUSE Rancher是德国SUSE公司的一个Kubernetes管理平台。 SUSE Rancher存在信任管理问题漏洞,该漏洞源于使用自签名CA证书并在未传递–cacert标志的情况下向Rancher CLI登录命令传递-skip-verify标志,可能导致CLI尝试获取存储在Rancher设置cacerts中的CA证书。
CVSS Information
N/A
Vulnerability Type
N/A