CVE Vulnerabilities

CVE-2017-7297

Published: Mar 29, 2017 | Modified: Apr 13, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.

Affected Software

Name Vendor Start Version End Version
Rancher Suse 1.2.0 (including) 1.2.4 (excluding)
Rancher Suse 1.3.0 (including) 1.3.5 (excluding)
Rancher Suse 1.4.0 (including) 1.4.3 (excluding)
Rancher Suse 1.5.0 (including) 1.5.3 (excluding)

References