CVE-2019-12274
Last modified
CVE-2019-12274 is a vulnerability of currently unknown severity. In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml.. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Rancher | >= 1.0.0, <= 1.6.28 |
| Suse | Rancher | >= 2.0.0, <= 2.2.3 |
References
- https://forums.rancher.com/c/announcementsRelease Notes, Vendor Advisory
- https://forums.rancher.com/t/rancher-release-v2-2-4-addresses-rancher-cve-2019-12274-and-cve-2019-12303/14466Release Notes, Vendor Advisory
- https://forums.rancher.com/c/announcementsRelease Notes, Vendor Advisory
- https://forums.rancher.com/t/rancher-release-v2-2-4-addresses-rancher-cve-2019-12274-and-cve-2019-12303/14466Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12274?
How severe is CVE-2019-12274?
How do I fix CVE-2019-12274?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12269Enigmail before 2.0.11 allows PGP signature spoofing: for an…
- CVE-2019-1227An information disclosure vulnerability exists when the Wind…5.5
- CVE-2019-12270OpenText Brava! Enterprise and Brava! Server 7.5 through 16.…
- CVE-2019-12271Sandline Centraleyezer (On Premises) allows unrestricted Fil…9.8
- CVE-2019-12272In OpenWrt LuCI through 0.10, the endpoints admin/status/rea…
- CVE-2019-12273OutSystems Platform 10 through 11 allows ImageResourceDetail…6.5
- CVE-2019-12276A Path Traversal vulnerability in Controllers/LetsEncryptCon…
- CVE-2019-12277Blogifier 2.3 before 2019-05-11 does not properly restrict A…
- CVE-2019-12278Opera through 53 on Android allows Address Bar Spoofing. Cha…4.3
- CVE-2019-12279Nagios XI 5.6.1 allows SQL injection via the username parame…
- CVE-2019-1228An information disclosure vulnerability exists when the Wind…5.5
- CVE-2019-12280PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path…
Are you affected by CVE-2019-12274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
