Skip to content

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-q82v-h4rq-5c86 #3983

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-q82v-h4rq-5c86 references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the .username field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts. Specifically:

  • Username takeover: A user with permission to update another user’s resource can set its .username to "admin", preventing both the legitimate admin and the affected user from logging in, as Rancher enforces uniqueness at login time.
  • Account lockout: A user with update permissions on the admin account can change the ad...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      non_go_versions:
        - introduced: 2.9.0
        - fixed: 2.9.12
        - introduced: 2.10.0
        - fixed: 2.10.10
        - introduced: 2.11.0
        - fixed: 2.11.6
        - introduced: 2.12.0
        - fixed: 2.12.2
      vulnerable_at: 1.6.30
summary: Rancher update on users can deny the service to the admin in github.com/rancher/rancher
cves:
    - CVE-2024-58260
ghsas:
    - GHSA-q82v-h4rq-5c86
references:
    - advisory: https://github.com/advisories/GHSA-q82v-h4rq-5c86
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86
source:
    id: GHSA-q82v-h4rq-5c86
    created: 2025-09-26T14:01:41.773194739Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions