A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" or "Impersonate-Group" headers. This issue affects: Rancher versions prior to 2.5.9. Rancher versions prior to 2.4.16.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1271 A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" or "Impersonate-Group" headers. This issue affects: Rancher versions prior to 2.5.9. Rancher versions prior to 2.4.16.
Github GHSA Github GHSA GHSA-pvxj-25m6-7vqr Rancher Privilege escalation vulnerability via malicious "Connection" header
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2024-09-17T02:26:40.038Z

Reserved: 2021-05-03T00:00:00

Link: CVE-2021-31999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-15T09:15:08.210

Modified: 2024-11-21T06:06:41.113

Link: CVE-2021-31999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses