CVE-2021-25320: Rancher: Cloud credentials can be used through proxy API by users without access
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.
Other sources
A vulnerability was discovered in Rancher 2.2.0 through the aforementioned patched versions, where cloud credentials weren't being properly validated through the Rancher API. Specifically through a proxy designed to communicate with cloud providers. Any Rancher user that was logged-in and aware of a cloud-credential ID that was valid for a given cloud provider, could call that cloud provider's API through the proxy API, and the cloud-credential would be attached. The exploit is limited to valid Rancher users. There is not a direct mitigation outside of upgrading to the patched Rancher versions.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25320?
CVE-2021-25320 is an Improper Access Control vulnerability in Rancher that allows users to make requests to cloud providers by creating requests with the cloud-credential ID.
What versions of Rancher are affected by CVE-2021-25320?
Rancher versions prior to 2.5.9 and versions up to 2.4.16 are affected by CVE-2021-25320.
What is the severity of CVE-2021-25320?
CVE-2021-25320 has a severity keyword of 'critical' and a severity value of 9.9.
How can I fix CVE-2021-25320?
To fix CVE-2021-25320, users should update Rancher to version 2.5.9 or later.