
Cloud Vulnerability DB
A community-led vulnerabilities database
An Improper Access Control vulnerability (CVE-2021-25320) was discovered in Rancher that allows users in the cluster to make requests to cloud providers by creating requests with the cloud-credential ID. The vulnerability affects Rancher versions prior to 2.5.9 and versions prior to 2.4.16. The issue was disclosed on July 15, 2021, and received a CVSS v3.0 Base Score of 9.9, indicating a critical severity level (NVD).
The vulnerability stems from an authentication bypass where Rancher would attach the requested credentials without performing additional verification checks. When exploited, users within the cluster could access cloud provider resources by utilizing the cloud-credential ID, effectively bypassing intended access controls. The vulnerability has been assigned a CVSS v3.0 Base Score of 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating network attackability, low attack complexity, and high impact across confidentiality, integrity, and availability (Qualys Research).
The vulnerability allows unauthorized access to cloud provider resources, potentially enabling attackers to compromise cloud infrastructure and access sensitive data. With a CVSS score of 9.9, the impact is considered critical as it could lead to complete compromise of affected systems and data (NVD).
The vulnerability has been confirmed as exploitable with low complexity, requiring only network access and low privileges. The attack vector is network-based, and no user interaction is required for exploitation (Qualys Research).
The vulnerability has been patched in Rancher versions 2.5.9 and 2.4.16. Organizations running affected versions should upgrade to these or later versions immediately to address the security issue (SUSE Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."