在 Rancher Manager 中发现了一个缺陷:当非管理员调用方提供一个指向其他用户的标签选择器时, Token 存储层会丢弃其内部的 owner 过滤器,而不是返回空结果。因此,任何已认证用户都可以列出并监视其他所有用户的 Token,从而泄露 Token 的元数据以及存储的加盐哈希值(bearer token 的加盐哈希)。 此问题影响以下版本的 Rancher:2.15.1 之前。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71404 | 8.7 HIGH | Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation o |
| CVE-2026-75033 | 7.7 HIGH | Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing |
| CVE-2026-75034 | 7.4 HIGH | Rancher: SAML Assertion Replay |
| CVE-2026-71403 | 6.1 MEDIUM | Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind |
| CVE-2026-75036 | 5.3 MEDIUM | Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing |
No comments yet