Skip to content

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-2v2w-8v8c-wcm9 #3391

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-2v2w-8v8c-wcm9 references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

A vulnerability has been identified within Rancher UI that allows a malicious actor to perform a Stored XSS attack through the cluster description field.

Please consult the associated MITRE ATT&CK - Technique - Drive-by Compromise for further information about this category of attack.

Patches

The fix introduces new changes in the directives responsible for sanitizing HTML code before rendering.

We replaced the v-tooltip directive with the v-clean-tooltip directive.

Patched versions include releases 2.9.4 and 2.10.0.

##...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      non_go_versions:
        - introduced: 2.9.0
        - fixed: 2.9.4
      vulnerable_at: 1.6.30
summary: Rancher UI has Stored Cross-site Scripting vulnerability in github.com/rancher/rancher
cves:
    - CVE-2024-52281
ghsas:
    - GHSA-2v2w-8v8c-wcm9
references:
    - advisory: https://github.com/advisories/GHSA-2v2w-8v8c-wcm9
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-2v2w-8v8c-wcm9
source:
    id: GHSA-2v2w-8v8c-wcm9
    created: 2025-01-14T23:01:37.510162132Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions