A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
{
"versions": [
{
"introduced": "2.10.0"
},
{
"fixed": "2.10.11"
},
{
"introduced": "2.11.0"
},
{
"fixed": "2.11.10"
},
{
"introduced": "2.12.0"
},
{
"fixed": "2.12.6"
},
{
"introduced": "2.13.0"
},
{
"fixed": "2.13.2"
}
]
}