in narrow circumstances through a man-in-the-middle (MITM) attack. An
attacker would need to have control of an expired domain or execute a
DNS spoofing/hijacking attack against the domain to exploit this
vulnerability. The targeted domain is the one used as the Rancher URL.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2807 | A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL. |
Github GHSA |
GHSA-h4h5-9833-v2p4 | Rancher agents can be hijacked by taking over the Rancher Server URL |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 16 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse rancher |
|
| CPEs | cpe:2.3:a:suse:rancher:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Suse
Suse rancher |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL. | |
| Title | Rancher agents can be hijacked by taking over the Rancher Server URL | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-10-16T14:25:43.445Z
Reserved: 2024-01-04T12:38:34.023Z
Link: CVE-2024-22030
Updated: 2024-10-16T14:25:35.997Z
Status : Deferred
Published: 2024-10-16T14:15:04.753
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-22030
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA