CVE-2018-20321
Last modified
CVE-2018-20321 is a vulnerability of currently unknown severity. An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. EPSS estimates a 1.80% chance of exploitation in the next 30 days.
Description
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. This could be mitigated by isolating the default namespace in a separate project, where only cluster admins can be given permissions to access. As of 2018-12-20, this bug affected ALL clusters created or imported by Rancher.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Rancher | >= 2.0.0, <= 2.1.5 |
References
- https://forums.rancher.com/c/announcementsVendor Advisory
- https://forums.rancher.com/c/announcementsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20321?
How severe is CVE-2018-20321?
How do I fix CVE-2018-20321?
Are you affected by CVE-2018-20321?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
