383
VMScore

CVE-2019-11881

Published: 10/06/2019 Updated: 13/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability exists in Rancher 2.1.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit malicious.rancher.site/upgrading" message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse rancher 2.1.4

Github Repositories

Exploit for CVE-2019-11881 (Rancher 2.1.4 Web Parameter Tampering)

VanCleef Rancher 214 Web Parameter Tampering (CVE-2019-11881) /vancleefrb rancher_ip rancher_port message_to_display (double-quoted) #Example: /vancleefrb 19216801 8080 "Rancher is outdated Please update following the instructions at 192168025/rancher-updating" MITRE CVE Announcement