Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-25320 - Cloud credentials can be used through Rancher's proxy by users without access #33589

Closed
cbron opened this issue Jul 13, 2021 · 0 comments
Milestone

Comments

@cbron
Copy link
Contributor

cbron commented Jul 13, 2021

A vulnerability was discovered in Rancher 2.2.0 through the aforementioned patched versions, where cloud credentials weren't being properly validated through the Rancher API. Specifically through a proxy designed to communicate with cloud providers. Any Rancher user that was logged-in and aware of a cloud-credential ID that was valid for a given cloud provider, could call that cloud provider's API through the proxy API, and the cloud-credential would be attached. The exploit is limited to valid Rancher users. There is not a direct mitigation outside of upgrading to the patched Rancher versions.

@Jono-SUSE-Rancher Jono-SUSE-Rancher changed the title PH Cloud credentials can be used through Rancher's proxy by users without access Jul 15, 2021
@Jono-SUSE-Rancher Jono-SUSE-Rancher added this to the v2.5.9 milestone Jul 15, 2021
@Jono-SUSE-Rancher Jono-SUSE-Rancher changed the title Cloud credentials can be used through Rancher's proxy by users without access CVE-2021-25320 - Cloud credentials can be used through Rancher's proxy by users without access Jul 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants