CVE-2019-11881
moderate-risk
Published 2019-06-10
A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading" message.
Do I need to act?
~
5.4% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.7/10
Medium
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (6)
Third Party Advisory
https://github.com/MauroEldritch/VanCleef
Third Party Advisory
https://github.com/MauroEldritch/VanCleef
32
/ 100
moderate-risk
Severity
19/34 · Moderate
Exploitability
8/34 · Low
Exposure
5/34 · Minimal