安全公告和 CVE
Rancher 致力于向社区披露我们产品的安全问题。我们会针对已解决的问题发布安全公告和 CVE(Common Vulnerabilities and Exposures,通用漏洞披露)。Rancher GitHub 上的安全页面也会发布新的安全公告。
ID | 描述 | 日期 | 解决 |
---|---|---|---|
CVE-2024-58260 | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the Manage Users permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 |
CVE-2024-58267 | The Rancher CLI is modified to print the requestId more visibly than as part of the login URL. It also adds a cli=true origin marker to the URL. The dashboard is modified to recognize the presence of the requestId and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 |
CVE-2025-54468 | Impersonate-* headers are removed for requests made through the /meta/proxy Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 |
CVE-2024-58259 | POSTs to the Rancher API endpoints are now limited to 1 Mi; this is configurable through the settings if you need a larger limit. The Rancher authentication endpoints are configured independently of the main public API (as you might need bigger payloads in the other API endpoints). Suppose you need to increase the maximum allowed payload for authentication. In that case, you can set the environment variable CATTLE_AUTH_API_BODY_LIMIT to a quantity, e.g., 2 Mi, which would allow larger payloads for the authentication endpoints. | 28 Aug 2025 | Rancher v2.12.1, v2.11.5, v2.10.9 and v2.9.11 |
CVE-2024-52284 | Following a recent change excluding Helm values files from bundles, an edge case subsisted where the values files referenced in fleet.yaml with your directory name (e.g., my-dir/values.yaml instead of values.yaml ) would not be excluded, which would potentially expose confidential data in bundle resources. Helm values files are now excluded from bundle resources regardless of how you reference them. | 28 Aug 2025 | Rancher v2.12.1, v2.11.5 and v2.10.9 |