In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/rancher/rancher/pkg/controllers/dashboard/helm
to version 2.8.10, 2.9.4 or higher.
Affected versions of this package are vulnerable to Information Exposure due to the storage of Helm values directly into the Apps
Custom Resource Definition. An attacker can access sensitive information by exploiting GET
access to the Apps' CRD or by setting the audit level to 2 or above.
Admins who are enable to upgrade to the fixed version are advised to limit the impact by reducing the amount of users who can get or list the Apps’ CRD. Additionally, the same applies to the auditing logs if the Rancher Manager has audit logs enabled and set to level 2 or above.