File tree 1 file changed +31
-0
lines changed
1 file changed +31
-0
lines changed Original file line number Diff line number Diff line change
1
+ packages :
2
+ - module : github.com/rancher/rancher
3
+ package : github.com/rancher/rancher/server
4
+ symbols :
5
+ - Start
6
+ versions :
7
+ - fixed : 2.2.5-rc6.0.20190621200032-0ddffe484adc+incompatible
8
+ vulnerable_at : 2.2.5-rc6.0.20190621195844-88e9e38dc862+incompatible
9
+ - module : github.com/rancher/rancher
10
+ package : github.com/rancher/rancher/pkg/clusterrouter
11
+ symbols :
12
+ - Router.ServeHTTP
13
+ versions :
14
+ - fixed : 2.2.5-rc6.0.20190621200032-0ddffe484adc+incompatible
15
+ vulnerable_at : 2.2.5-rc6.0.20190621195844-88e9e38dc862+incompatible
16
+ description : |
17
+ Rancher 2 is vulnerable to a Cross-Site Websocket Hijacking
18
+ attack that allows an exploiter to gain access to clusters managed by
19
+ Rancher.
20
+ published : 2021-05-18T15:42:40Z
21
+ last_modified : 2022-04-25T20:20:19Z
22
+ cves :
23
+ - CVE-2019-13209
24
+ ghsas :
25
+ - GHSA-xhg2-rvm8-w2jh
26
+ credit : Matt Belisle and Alex Stevenson at Workiva
27
+ links :
28
+ advisory : https://github.com/advisories/GHSA-xhg2-rvm8-w2jh
29
+ commit : https://github.com/rancher/rancher/commit/0ddffe484adccb9e37d9432e8e625d8ebbfb0088
30
+ context :
31
+ - https://forums.rancher.com/t/rancher-release-v2-2-5-addresses-rancher-cve-2019-13209/14801
You can’t perform that action at this time.
0 commit comments