CVE-2024-58267

8.0

SUSE · Rancher

Rancher Manager is susceptible to a phishing-based SAML authentication flaw in the CLI tool, allowing attackers to intercept and steal authentication tokens.

Executive summary

A critical authentication vulnerability in Rancher Manager allows attackers to perform phishing attacks to steal user tokens, potentially leading to unauthorized system access.

Vulnerability

This flaw involves insufficient verification of data authenticity within the Rancher CLI SAML authentication process. An attacker can manipulate the custom authentication protocol to capture session tokens from an authenticated user.

Business impact

The vulnerability poses a severe risk to organizational security by enabling unauthorized access to the Rancher management environment. Successful exploitation grants an attacker the ability to hijack administrative sessions, resulting in potential data exfiltration, unauthorized modification of infrastructure, and complete compromise of managed clusters. With a CVSS score of 8.0, this issue represents a significant threat to operational integrity.

Remediation

Immediate Action: Upgrade Rancher Manager to version 2.12.2, 2.11.6, 2.10.10, or 2.9.12 immediately to apply the vendor-supplied security fixes.

Proactive Monitoring: Review access logs for unusual CLI authentication patterns and monitor for anomalous token usage or unexpected administrative activity originating from verified user accounts.

Compensating Controls: Enforce strict phishing awareness training for all users and implement multi-factor authentication where possible to reduce the risk of credential interception.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for total system compromise, administrators must prioritize the application of the provided patches. Ensure all Rancher CLI users are updated to the corrected versions to prevent token theft and maintain the security posture of the container management environment.

More SUSE CVEs

Sources