← Back to browse · API

CVE-2021-25320

Severity
CRITICAL
CVSS
9.9
EPSS
0.00855
Risk score
39.9
CISA KEV
No
PoC
Yes
Published
2021-07-15
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-12217, GHSA-GQF8-RVRH-G7W6
Products
SUSE:Rancher Rancher <2.4.16, SUSE:Rancher Rancher <2.5.9, linux, suse
Sources
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2021-25320
euvd EUVD-2021-12217

Description

A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.

References