CVE-2019-6287: High severity suse rancher vulnerability
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6287?
CVE-2019-6287 is a vulnerability in Rancher 2.0.0 through 2.1.5 that allows project members to retain access to create, update, read, and delete namespaces in a project even after being removed from it.
How severe is CVE-2019-6287?
CVE-2019-6287 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2019-6287?
Rancher versions 2.0.0 through 2.1.5 are affected by CVE-2019-6287.
How can I fix CVE-2019-6287?
To fix CVE-2019-6287, upgrade to Rancher version 2.1.6 or 2.0.11 or later.
Where can I find more information about CVE-2019-6287?
More information about CVE-2019-6287 can be found on the Rancher forums (https://forums.rancher.com/c/announcements) and the Rancher blog (https://rancher.com/blog/2019/2019-01-29-explaining-security-vulnerabilities-addressed-in-rancher-v2-1-6-and-v2-0-11/).