Skip to content

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-mw39-9qc2-f7mg #4074

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-mw39-9qc2-f7mg references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

Note: The exploitation of this issue requires that the malicious user have access to Rancher’s audit log storage.

A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs. This happens in two different ways:

  1. Secret Annotation Leakage: When creating Kubernetes Secrets using the stringData field, the cleartext value is embedded in the kubectl.kubernetes.io/last-applied-configuration annotation. This annotation is inc...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      versions:
        - fixed: 0.0.0-20251013203444-50dc516a19ea
summary: Rancher exposes sensitive information through audit logs in github.com/rancher/rancher
cves:
    - CVE-2024-58269
ghsas:
    - GHSA-mw39-9qc2-f7mg
references:
    - advisory: https://github.com/advisories/GHSA-mw39-9qc2-f7mg
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg
    - fix: https://github.com/rancher/rancher/commit/26ad9216e94f77b5471f638256a6989030572adc
    - fix: https://github.com/rancher/rancher/commit/50dc516a19ea216e270f738912dc8d0c9ca99d5d
notes:
    - fix: 'github.com/rancher/rancher: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
    id: GHSA-mw39-9qc2-f7mg
    created: 2025-10-24T16:01:35.943369848Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions