Rancher Manager Cluster Import Endpoint Vulnerable to Command Injection
An early warning reports a critical command injection vulnerability in Rancher Manager's cluster import endpoint, potentially allowing attackers to execute arbitrary commands on control-plane nodes and gain full control over downstream Kubernetes clusters.
What happened
An early warning indicates a critical command injection vulnerability in the Rancher Manager cluster import endpoint. This vulnerability reportedly allows attackers to inject arbitrary YAML keys and execute malicious commands on control-plane nodes. Successful exploitation could lead to full control over downstream Kubernetes clusters. Affected versions include 2.14.0 to 2.14.1, 2.13.0 to 2.13.5, 2.12.0 to 2.12.9, 2.11.0 to 2.11.13, and 2.10.0 to 2.10.11. The issue appears to be fixed in versions 2.14.2, 2.13.6, 2.12.10, 2.11.14, and 2.10.12 respectively. It is under investigation whether versions prior to 2.10.0 are affected.
Professional software engineers using Rancher Manager are advised to review their clusters' logs and deployment logs for signs of malicious deployments. As a precaution, rotate all service accounts and credentials that may have been compromised. Consult the primary sources for the most accurate and up-to-date information on this vulnerability.
How 0Day mitigates this
rancher is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.