CVE-2021-25313: Rancher: XSS on /v3/cluster/
Published Mar 5, 2021
·Updated
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
Affected Software
4 affected componentsFixes available
go/github.com/rancher/rancher<2.3.11
2.3.11
go/github.com/rancher/rancher>=2.4.0<2.4.14
2.4.14
go/github.com/rancher/rancher>=2.5.0<2.5.6
2.5.6
SUSE rancher<2.5.6
Event History
Mar 5, 2021
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionSeverityWeakness
May 24, 2022
Advisory Published
05:43 PM
Frequently Asked Questions
1
What is CVE-2021-25313?
CVE-2021-25313 is an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in Rancher.
2
How does CVE-2021-25313 impact Rancher?
CVE-2021-25313 allows remote attackers to execute JavaScript via malicious links in Rancher.
3
Which versions of Rancher are affected by CVE-2021-25313?
Rancher versions prior to 2.5.6 are affected by CVE-2021-25313.
4
What is the severity of CVE-2021-25313?
CVE-2021-25313 has a severity value of 6.1, which is considered medium.
5
How can I fix CVE-2021-25313?
To fix CVE-2021-25313, update Rancher to version 2.5.6 or later.