{"id":"GHSA-xhg2-rvm8-w2jh","summary":"Rancher Vulnerable to Cross-site Request Forgery (CSRF)","details":"Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.","aliases":["CVE-2019-13209","GO-2022-0755"],"modified":"2026-09-10T03:49:14.900669706Z","published":"2021-05-18T15:42:40Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-05-17T16:37:55Z","nvd_published_at":"2019-09-04T14:15:00Z","cwe_ids":["CWE-352","CWE-79"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13209"},{"type":"WEB","url":"https://github.com/rancher/rancher/commit/0ddffe484adccb9e37d9432e8e625d8ebbfb0088"},{"type":"WEB","url":"https://forums.rancher.com/t/rancher-release-v2-2-5-addresses-rancher-cve-2019-13209/14801"},{"type":"PACKAGE","url":"https://github.com/rancher/rancher"}],"affected":[{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-xhg2-rvm8-w2jh/GHSA-xhg2-rvm8-w2jh.json"}},{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.1.0"},{"fixed":"2.1.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-xhg2-rvm8-w2jh/GHSA-xhg2-rvm8-w2jh.json"}},{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.2.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-xhg2-rvm8-w2jh/GHSA-xhg2-rvm8-w2jh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:H"}]}