Improper Certificate Validation Affecting github.com/rancher/steve/pkg/ui package, versions >=0.2.0 <0.2.1>=0.3.0 <0.3.3>=0.4.0 <0.4.4>=0.5.0 <0.5.13


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERSTEVEPKGUI-10292127
  • published2 Jun 2025
  • disclosed25 Apr 2025
  • creditUnknown

Introduced: 25 Apr 2025

CVE-2023-32198  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/steve/pkg/ui to version 0.2.1, 0.3.3, 0.4.4, 0.5.13 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation presented by the remote server during a TLS connection. An attacker can intercept and potentially alter communications by positioning themselves between the client and the server.

Note:

This is only exploitable if the ui-offline-preferred setting is manually set to remote.

Workaround

This vulnerability can be mitigated by ensuring that Steve is only used to connect to trusted servers.

References

CVSS Base Scores

version 4.0
version 3.1