Improper Authentication Affecting github.com/rancher/rancher/app package, versions >=2.0.0 <2.0.14 >=2.1.0 <2.1.9 >=2.2.0 <2.2.2


0.0
critical

Snyk CVSS

    Attack Complexity Low
    Confidentiality High
    Integrity High
    Availability High

    Threat Intelligence

    EPSS 0.34% (72nd percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-GOLANG-GITHUBCOMRANCHERRANCHERAPP-6673734
  • published 25 Apr 2024
  • disclosed 24 May 2022
  • credit Unknown

How to fix?

Upgrade github.com/rancher/rancher/app to version 2.0.14, 2.1.9, 2.2.2 or higher.

Overview

github.com/rancher/rancher/app is a complete container management platform

Affected versions of this package are vulnerable to Improper Authentication. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials.

Note:

This can be mitigated by deactivating the default admin user rather than completely deleting them.