← Back

CVE-2019-11881

nvd nist
Published: Jun 10, 2019Modified: Dec 4, 2024

JSON object

Loading...
4.7
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading" message.

Affected (1)

Products: Suse: Rancher
1 product
Rancher
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.1.4

References (6)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.