First published: Fri Mar 05 2021(Updated: )
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
Credit: meissner@suse.de meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/rancher/rancher | <2.3.11 | 2.3.11 |
go/github.com/rancher/rancher | >=2.4.0<2.4.14 | 2.4.14 |
go/github.com/rancher/rancher | >=2.5.0<2.5.6 | 2.5.6 |
SUSE Rancher | <2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25313 is an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in Rancher.
CVE-2021-25313 allows remote attackers to execute JavaScript via malicious links in Rancher.
Rancher versions prior to 2.5.6 are affected by CVE-2021-25313.
CVE-2021-25313 has a severity value of 6.1, which is considered medium.
To fix CVE-2021-25313, update Rancher to version 2.5.6 or later.