GO-2022-0755

See a problem?
Source
https://pkg.go.dev/vuln/GO-2022-0755
Import Source
https://vuln.go.dev/ID/GO-2022-0755.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2022-0755
Aliases
Published
2021-05-18T15:42:40Z
Modified
2024-05-20T16:03:47Z
Summary
Cross-site request forgery in github.com/rancher/rancher
Details

Rancher 2 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher.

References
Credits
    • Matt Belisle
    • Alex Stevenson at Workiva

Affected packages

Go / github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.5-rc6.0.20190621200032-0ddffe484adc+incompatible

Ecosystem specific

{
    "imports": [
        {
            "path": "github.com/rancher/rancher/server",
            "symbols": [
                "Start"
            ]
        },
        {
            "path": "github.com/rancher/rancher/pkg/clusterrouter",
            "symbols": [
                "Router.ServeHTTP"
            ]
        }
    ]
}