github.com/rancher/rancher vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-45157Highgithub.com/rancher/rancher: Exposure of vSphere's CPI and CSI credentials in RancherCVE-2023-32197Criticalgithub.com/rancher/rancher: Rancher allows privilege escalation in Windows nodes due to Insecure Access Control ListsCVE-2024-22030Highgithub.com/rancher/rancher: Rancher agents can be hijacked by taking over the Rancher Server URLCVE-2024-22032Highgithub.com/rancher/rancher: Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpecCVE-2023-32196Highgithub.com/rancher/rancher: Rancher's External RoleTemplates can lead to privilege escalationCVE-2023-22650Highgithub.com/rancher/rancher: Rancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderCVE-2021-25318Highgithub.com/rancher/rancher: Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resourcesCVE-2021-31999Highgithub.com/rancher/rancher: Rancher Privilege escalation vulnerability via malicious "Connection" headerCVE-2021-36776Highgithub.com/rancher/rancher: Rancher's Steve API Component Improper authorization check allows privilege escalationCVE-2021-36775Highgithub.com/rancher/rancher: Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authenticationCVE-2023-22649Highgithub.com/rancher/rancher: Rancher 'Audit Log' leaks sensitive informationCVE-2023-32194Highgithub.com/rancher/rancher: Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'CVE-2023-22647Criticalgithub.com/rancher/rancher: Rancher vulnerable to Privilege Escalation via manipulation of SecretsCVE-2022-43760Mediumgithub.com/rancher/rancher: Rancher UI has multiple Cross-Site Scripting (XSS) issuesCVE-2020-10676Highgithub.com/rancher/rancher: Rancher users retain access after moving namespaces into projects they don't have access toCVE-2023-22651Criticalgithub.com/rancher/rancher: Rancher Webhook is misconfigured during upgrade processGHSA-C45C-39F6-6GW9Highgithub.com/rancher/rancher: Rancher generated tokens not revoked after modifications made to authentication providerCVE-2022-43757Highgithub.com/rancher/rancher: Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objectsCVE-2022-43758Mediumgithub.com/rancher/rancher: Command injection in Rancher Git packageCVE-2022-21953Highgithub.com/rancher/rancher: Authenticated user can gain unauthorized shell pod and kubectl access in the local clusterCVE-2022-43759Highgithub.com/rancher/rancher: Privilege escalation in project role template binding (PRTB) and -promoted rolesCVE-2022-43755Highgithub.com/rancher/rancher: Rancher cattle-token is predictableCVE-2021-36782Criticalgithub.com/rancher/rancher: Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentialsCVE-2021-25313Mediumgithub.com/rancher/rancher: Rancher Cross-site Scripting VulnerabilityCVE-2019-11202Criticalgithub.com/rancher/rancher: Rancher Recreates Default User With Known Password Despite Deletion

Stop the waste.
Protect your environment with Kodem.