| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2. |
| Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster. |
| Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
| Memory Corruption when processing registry values with incorrect types using a direct query method. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; never assigned. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
| Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |