Rancher Fleet是Rancher公司的一款容器集群监控与管理平台。 Rancher Fleet存在服务端请求伪造漏洞,该漏洞源于当GitRepo资源未设置helmRepoURLRegex字段时,缺少过滤机制,导致Helm身份验证凭据(BasicAuth)被转发到fleet.yaml文件中helm.repo字段指定的任意URL,可能允许攻击者推送到fleet监控的git仓库并泄露helm访问凭据。以下版本受到影响:0.12.15版本之前的0.12.x版本、0.13.11版本之前的0.13.x版本、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44934 | Exposed tokens in SUSE Rancher AI Agent logs | |
| CVE-2026-44937 | SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Reposit |
No comments yet