CVE-2019-12303: High severity suse rancher vulnerability
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12303?
CVE-2019-12303 is a vulnerability in Rancher 2 through 2.2.3 where project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
How severe is CVE-2019-12303?
CVE-2019-12303 is considered high severity with a CVSS score of 8.8.
Which software versions are affected by CVE-2019-12303?
Versions 2.0.0 through 2.2.3 of Rancher are affected by CVE-2019-12303.
How can project owners exploit CVE-2019-12303?
Project owners can exploit CVE-2019-12303 by injecting additional fluentd configuration to read files or execute arbitrary commands within the fluentd container of Rancher 2 through 2.2.3.
Is there a fix available for CVE-2019-12303?
Yes, a fix for CVE-2019-12303 is available in Rancher release v2.2.4.