First published: Thu Jun 06 2019(Updated: )
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Rancher | >=2.0.0<=2.2.3 | |
go/github.com/rancher/rancher | >=2.0.0<=2.2.3 | 2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12303 is a vulnerability in Rancher 2 through 2.2.3 where project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
CVE-2019-12303 is considered high severity with a CVSS score of 8.8.
Versions 2.0.0 through 2.2.3 of Rancher are affected by CVE-2019-12303.
Project owners can exploit CVE-2019-12303 by injecting additional fluentd configuration to read files or execute arbitrary commands within the fluentd container of Rancher 2 through 2.2.3.
Yes, a fix for CVE-2019-12303 is available in Rancher release v2.2.4.