Skip to content

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-v3vj-5868-2ch2 #3984

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-v3vj-5868-2ch2 references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

Rancher Manager deployments without SAML authentication enabled are not affected by this vulnerability.

An attacker can generate a phishing SAML login URL which contains a publicKey and requestId controlled by the attacker. The attacker can then give the link to another user (eg: admin) and if the victim goes ...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      non_go_versions:
        - introduced: 2.9.0
        - fixed: 2.9.12
        - introduced: 2.10.0
        - fixed: 2.10.10
        - introduced: 2.11.0
        - fixed: 2.11.6
        - introduced: 2.12.0
        - fixed: 2.12.2
      vulnerable_at: 1.6.30
summary: Rancher CLI SAML authentication is vulnerable to phishing attacks in github.com/rancher/rancher
cves:
    - CVE-2024-58267
ghsas:
    - GHSA-v3vj-5868-2ch2
references:
    - advisory: https://github.com/advisories/GHSA-v3vj-5868-2ch2
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2
source:
    id: GHSA-v3vj-5868-2ch2
    created: 2025-09-26T14:01:42.63616572Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions