漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Long-lived Rancher registration token exposed in plaintext
Vulnerability Description
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
敏感数据的明文存储
Vulnerability Title
Rancher 加密问题漏洞
Vulnerability Description
Rancher是Rancher组织开源的一个面向企业环境的容器编排与管理平台。 Rancher 2.14.0版本至2.14.4之前版本和2.13.0版本至2.13.8之前版本存在加密问题漏洞,该漏洞源于Rancher向加入下游集群的节点和代理颁发长期有效的注册令牌,这些令牌以明文存储且无过期时间,可能被恶意用户通过Rancher API、etcd、存储自动化或节点直接文件访问获取,并用于注册恶意节点到集群中。
CVSS Information
N/A
Vulnerability Type
N/A