Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-25320

A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.1%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 4.0
Products affected by CVE-2021-25320


Contact Us

Shodan ® - All rights reserved