Description
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mc24-7m59-4q5p | Rancher CLI skips TLS verification on Rancher CLI login command |
References
History
Tue, 03 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse rancher |
|
| CPEs | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Suse
Suse rancher |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts. | |
| Title | Rancher CLI skips TLS verification on Rancher CLI login command | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-26T14:44:07.081Z
Reserved: 2025-12-09T14:05:21.453Z
Link: CVE-2025-67601
Updated: 2026-02-25T21:04:30.404Z
Status : Analyzed
Published: 2026-02-25T11:16:02.643
Modified: 2026-03-03T16:26:32.240
Link: CVE-2025-67601
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA