CVE-2017-7297
29.03.2017, 00:59
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.Enginsight
Vendor | Product | Version |
---|---|---|
suse | rancher | 1.2.0 ≤ 𝑥 < 1.2.4 |
suse | rancher | 1.3.0 ≤ 𝑥 < 1.3.5 |
suse | rancher | 1.4.0 ≤ 𝑥 < 1.4.3 |
suse | rancher | 1.5.0 ≤ 𝑥 < 1.5.3 |
𝑥
= Vulnerable software versions