Browse Security Advisories
Security Advisories for github.com/rancher/rancher Clear Filters
High
3 months ago
Rancher users who can create Projects can gain access to arbitrary projects
go
github.com/rancher/rancher
Critical
4 months ago
Rancher: Restricted Administrator can change Administrator's passwords
go
github.com/rancher/rancher
High
5 months ago
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
go
github.com/rancher/rancher
High
5 months ago
Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API
go
github.com/rancher/rancher
Moderate
5 months ago
Rancher's SAML-based login via CLI can be denied by unauthenticated users
go
github.com/rancher/rancher
High
7 months ago
Rancher UI has Stored Cross-site Scripting vulnerability
go
github.com/rancher/rancher
Moderate
8 months ago
Rancher Helm Applications may have sensitive values leaked
go
github.com/rancher/rancher
Critical
9 months ago
Rancher Remote Code Execution via Cluster/Node Drivers
go
github.com/rancher/rancher
High
9 months ago
Exposure of vSphere's CPI and CSI credentials in Rancher
go
github.com/rancher/rancher
Critical
9 months ago
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
go
github.com/rancher/rancher
High
10 months ago
Rancher agents can be hijacked by taking over the Rancher Server URL
go
github.com/rancher/rancher
High
about 1 year ago
Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec
go
github.com/rancher/rancher
High
about 1 year ago
Rancher's External RoleTemplates can lead to privilege escalation
go
github.com/rancher/rancher
High
about 1 year ago
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider
go
github.com/rancher/rancher
High
over 1 year ago
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
go
github.com/rancher/rancher
High
over 1 year ago
Rancher Privilege escalation vulnerability via malicious "Connection" header
go
github.com/rancher/rancher
High
over 1 year ago
Rancher's Steve API Component Improper authorization check allows privilege escalation
go
github.com/rancher/rancher
High
over 1 year ago
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
go
github.com/rancher/rancher
High
over 1 year ago
Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'
go
github.com/rancher/rancher
Critical
about 2 years ago
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
go
github.com/rancher/rancher
Moderate
about 2 years ago
Rancher UI has multiple Cross-Site Scripting (XSS) issues
go
github.com/rancher/rancher
High
about 2 years ago
Rancher users retain access after moving namespaces into projects they don't have access to
go
github.com/rancher/rancher
Critical
over 2 years ago
Rancher Webhook is misconfigured during upgrade process
go
github.com/rancher/rancher
High
over 2 years ago
Rancher generated tokens not revoked after modifications made to authentication provider
go
github.com/rancher/rancher
High
over 2 years ago
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
go
github.com/rancher/rancher
High
over 2 years ago
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
go
github.com/rancher/rancher
High
over 2 years ago
Privilege escalation in project role template binding (PRTB) and -promoted roles
go
github.com/rancher/rancher
Critical
almost 3 years ago
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
go
github.com/rancher/rancher
Critical
about 3 years ago
Rancher Recreates Default User With Known Password Despite Deletion
go
github.com/rancher/rancher
High
about 3 years ago
Rancher code injection via fluentd config commands
go
github.com/rancher/rancher
High
about 3 years ago
Rancher Project Members Have Continued Access to Namespaces After Being Removed From Them
go
github.com/rancher/rancher
Moderate
about 3 years ago
Privilege escalation for users with create/update permissions in Global Roles in Rancher
go
github.com/rancher/rancher
High
about 3 years ago
Exposure of repository credentials to external third-party sources in Rancher
go
github.com/rancher/rancher
High
about 3 years ago
Write access to the catalog for any user when restricted-admin role is enabled in Rancher
go
github.com/rancher/rancher
High
about 4 years ago
Rancher Vulnerable to Cross-site Request Forgery (CSRF)
go
github.com/rancher/rancher
Filter by Severity
Filter by Ecosystem
maven
6,630
packagist
5,356
pypi
4,831
npm
4,188
go
2,794
nuget
1,700
cargo
1,065
rubygems
918
hex
37
swift
35
actions
32
pub
10
Filter by Package
tensorflow
433
tensorflow-gpu
427
tensorflow-cpu
423
moodle/moodle
418
magento/community-edition
300
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
239
typo3/cms
190
org.apache.tomcat:tomcat
138
pimcore/pimcore
120
dolibarr/dolibarr
116
github.com/mattermost/mattermost/server/v8
115
typo3/cms-core
111
phpmyadmin/phpmyadmin
107
Django
107
drupal/core
103
com.liferay.portal:release.portal.bom
100
magento/project-community-edition
100
microweber/microweber
99
silverstripe/framework
92
com.liferay.portal:release.dxp.bom
91
apache-airflow
85
drupal/drupal
83
librenms/librenms
82
thorsten/phpmyfaq
73
Plone
72
com.fasterxml.jackson.core:jackson-databind
69
symfony/symfony
69
concrete5/concrete5
65
github.com/usememos/memos
65
salt
65
ansible
63
actionpack
61
apache-superset
57
shopware/platform
57
org.apache.struts:struts2-core
57
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
51
org.keycloak:keycloak-core
50
nova
48
baserproject/basercms
47
django
46
org.apache.tomcat.embed:tomcat-embed-core
46
nokogiri
46
shopware/core
45
gradio
44
github.com/rancher/rancher
44
mautic/core
44
vyper
44
matrix-synapse
42
rdiffweb
42
nilsteampassnet/teampass
42
mantisbt/mantisbt
41
org.keycloak:keycloak-services
41
k8s.io/kubernetes
41
org.xwiki.platform:xwiki-platform-oldcore
41
plone
41
showdoc/showdoc
41
org.elasticsearch:elasticsearch
41
github.com/hashicorp/vault
40
froxlor/froxlor
40
intelliants/subrion
39
github.com/mattermost/mattermost-server/v6
39
directus
38
com.thoughtworks.xstream:xstream
37
snipe/snipe-it
36
net.mingsoft:ms-mcms
36
com.jfinal:jfinal
36
moin
35
io.undertow:undertow-core
34
github.com/answerdev/answer
34
org.jenkins-ci.plugins:script-security
34
zendframework/zendframework1
34
parse-server
33
keystone
32
gogs.io/gogs
32
github.com/cilium/cilium
31
github.com/argoproj/argo-cd/v2
31
github.com/argoproj/argo-cd
31
opencv-python
31
Pillow
31
github.com/hashicorp/nomad
31
opencv-contrib-python
31
getgrav/grav
30
shopware/shopware
30
rack
29
github.com/docker/docker
29
github.com/hashicorp/consul
29
github.com/mattermost/mattermost-server
29
org.apache.solr:solr-core
28
mediawiki/core
28
electron
28
org.opencms:opencms-core
27
centreon/centreon
27
pillow
26
openssl-src
26
org.springframework.security:spring-security-core
26
next
26
prestashop/prestashop
26
rubygems-update
25
contao/core-bundle
25
org.eclipse.jetty:jetty-server
25
open-webui
25
github.com/traefik/traefik/v2
24
surrealdb
24
getkirby/cms
24
pocketmine/pocketmine-mp
24
magento/core
24
org.keycloak:keycloak-parent
24
laravel/framework
23
simplesamlphp/simplesamlphp
23
puppet
23
vllm
23
grumpydictator/firefly-iii
23
phpoffice/phpexcel
23
remdex/livehelperchat
23
zendframework/zendframework
23
org.bouncycastle:bcprov-jdk14
22
tribalsystems/zenario
22
Microsoft.AspNetCore.App.Runtime.win-x86
22
Microsoft.AspNetCore.App.Runtime.win-x64
22
org.apache.openmeetings:openmeetings-parent
22
DotNetNuke.Core
22
@openzeppelin/contracts-upgradeable
22
ckb
22
org.apache.nifi:nifi
21
github.com/ethereum/go-ethereum
21
org.apache.tomcat:tomcat-catalina
21
@openzeppelin/contracts
21
phpoffice/phpspreadsheet
21
glance
21
github.com/goharbor/harbor
21
activerecord
21
Microsoft.AspNetCore.App.Runtime.win-arm
21
golang.org/x/net
20
funadmin/funadmin
20
aim
20
code.gitea.io/gitea
20
wasmtime
20
cockpit-hq/cockpit
20
org.cloudfoundry.identity:cloudfoundry-identity-server
20
langchain
20
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
19
neutron
19
github.com/zitadel/zitadel
19
helm.sh/helm/v3
19
deno
19
Microsoft.AspNetCore.App.Runtime.linux-arm
19
Microsoft.AspNetCore.App.Runtime.linux-arm64
19
Microsoft.AspNetCore.App.Runtime.linux-x64
19
Microsoft.AspNetCore.App.Runtime.osx-x64
19
Microsoft.AspNetCore.App.Runtime.win-arm64
19
pyload-ng
19
org.apache.tomcat:tomcat-coyote
19
org.xwiki.platform:xwiki-platform-web-templates
19
genix/cms
18
contao/contao
18
topthink/framework
18
forkcms/forkcms
18
cobbler
18
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
18
mercurial
18
mindsdb
18
com.vaadin:vaadin-bom
18
symfony/security
17
cakephp/cakephp
17
notebook
17
calibreweb
17
opencart/opencart
17
org.apache.geode:geode-core
17
openmage/magento-lts
17
OctoPrint
17
org.apache.inlong:manager-pojo
17
org.springframework:spring-core
17
cryptography
17
francoisjacquet/rosariosis
17
typo3/cms-backend
17
yetiforce/yetiforce-crm
17
ezsystems/ezpublish-kernel
17
phpbb/phpbb
16
org.apache.ranger:ranger
16
github.com/traefik/traefik/v3
16
paddlepaddle
16
PaddlePaddle
16
org.apache.activemq:activemq-client
16
lollms
16
org.apache.jspwiki:jspwiki-main
16
rusqlite
16
sequelize
16
org.apache.dubbo:dubbo
16
Microsoft.NetCore.App.Runtime.win-arm
16
github.com/openfga/openfga
16
Microsoft.NetCore.App.Runtime.win-arm64
16
Microsoft.NetCore.App.Runtime.win-x64
16
Microsoft.NetCore.App.Runtime.win-x86
16
org.bouncycastle:bcprov-jdk15
16
october/system
16
tinymce
16
ethyca-fides
16