Skip to content

Commit cd6fa17

Browse files
tatianabjulieqiu
authored andcommitted
x/vulndb: add reports/GO-2022-0755.yaml for CVE-2019-13209
Fixes #755 Change-Id: I4f2898da2c0ee8b859a5a2f5d093e079b7988d0b Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/421055 Reviewed-by: Damien Neil <[email protected]> Reviewed-by: Julie Qiu <[email protected]>
1 parent 6e0f990 commit cd6fa17

File tree

1 file changed

+31
-0
lines changed

1 file changed

+31
-0
lines changed

reports/GO-2022-0755.yaml

+31
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
packages:
2+
- module: github.com/rancher/rancher
3+
package: github.com/rancher/rancher/server
4+
symbols:
5+
- Start
6+
versions:
7+
- fixed: 2.2.5-rc6.0.20190621200032-0ddffe484adc+incompatible
8+
vulnerable_at: 2.2.5-rc6.0.20190621195844-88e9e38dc862+incompatible
9+
- module: github.com/rancher/rancher
10+
package: github.com/rancher/rancher/pkg/clusterrouter
11+
symbols:
12+
- Router.ServeHTTP
13+
versions:
14+
- fixed: 2.2.5-rc6.0.20190621200032-0ddffe484adc+incompatible
15+
vulnerable_at: 2.2.5-rc6.0.20190621195844-88e9e38dc862+incompatible
16+
description: |
17+
Rancher 2 is vulnerable to a Cross-Site Websocket Hijacking
18+
attack that allows an exploiter to gain access to clusters managed by
19+
Rancher.
20+
published: 2021-05-18T15:42:40Z
21+
last_modified: 2022-04-25T20:20:19Z
22+
cves:
23+
- CVE-2019-13209
24+
ghsas:
25+
- GHSA-xhg2-rvm8-w2jh
26+
credit: Matt Belisle and Alex Stevenson at Workiva
27+
links:
28+
advisory: https://github.com/advisories/GHSA-xhg2-rvm8-w2jh
29+
commit: https://github.com/rancher/rancher/commit/0ddffe484adccb9e37d9432e8e625d8ebbfb0088
30+
context:
31+
- https://forums.rancher.com/t/rancher-release-v2-2-5-addresses-rancher-cve-2019-13209/14801

0 commit comments

Comments
 (0)