CVE-2019-11202
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.
Se detectó un problema que afecta a las siguientes versiones de Rancher: versiones v2.0.0 hasta v2.0.13, versiones v2.1.0 hasta v2.1.8 y versiones v2.2.0 hasta 2.2.1. Cuando Rancher se inicia por primera vez, crea un usuario administrador por defecto con una contraseña conocida. Después de la configuración inicial, el administrador de Rancher puede elegir eliminar este usuario administrador por defecto. Si se reinicia Rancher, el usuario administrador por defecto se volverá a crear con la contraseña predeterminada conocida. Un atacante podría explotar esto mediante el inicio de sesión con las credenciales de administrador predeterminadas. Esto se puede mitigar mediante la desactivación del usuario administrador por defecto en lugar de completar su eliminación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-11 CVE Reserved
- 2019-07-30 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://forums.rancher.com/c/announcements | 2022-04-13 | |
https://rancher.com/docs/rancher/v2.x/en/security | 2022-04-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Suse Search vendor "Suse" | Rancher Search vendor "Suse" for product "Rancher" | >= 2.0.0 <= 2.0.13 Search vendor "Suse" for product "Rancher" and version " >= 2.0.0 <= 2.0.13" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Rancher Search vendor "Suse" for product "Rancher" | >= 2.1.0 <= 2.1.8 Search vendor "Suse" for product "Rancher" and version " >= 2.1.0 <= 2.1.8" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Rancher Search vendor "Suse" for product "Rancher" | >= 2.2.0 <= 2.2.1 Search vendor "Suse" for product "Rancher" and version " >= 2.2.0 <= 2.2.1" | - |
Affected
|