Bug 1219982 (CVE-2024-22030)

Summary: CVE-2024-22030: Rancher and Fleet agents can be hijacked by taking over the Rancher Server URL
Product: [Novell Products] SUSE Security Incidents Reporter: Pietro Dell'Amore <pietro.dellamore>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Critical    
Priority: P5 - None CC: andy.pitcher, guilherme.macedo, jsegitz, meissner, pietro.dellamore
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://github.com/rancherlabs/embargoed-security/issues/452
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Marcus Meissner 2024-02-16 08:04:08 UTC
CVE-2024-22030
Comment 2 Marcus Meissner 2024-02-16 16:23:24 UTC
blog post is public
https://www.suse.com/c/rancher-security-update/
Comment 3 Thomas Leroy 2024-07-05 15:18:56 UTC
All done, closing.