CVE-2023-32192High· 8.3▾ TwilightRancher API Server Cross-site Scripting Vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.
The attack vector was identified as a Reflected XSS.
API Server propagates malicious payloads from user input to the UI, which renders the output. For example, a malicious URL gets rendered into a script that is executed on a page.
The changes addressed by this fix are:
url.URL.Patched versions include the following commits:
| Branch | Commit |
|---|---|
| master | 4fd7d82 |
| release/v2.8 | 69b3c2b |
| release/v2.8.s3 | a3b9e37 |
| release/v2.7 | 4e102cf |
| release/v2.7.s3 | 97a10a3 |
| release/v2.6 | 4df268e |
There is no direct mitigation besides updating API Server to a patched version.
If you have any questions or comments about this advisory:
github.com/rancher/apiserver < 0.0.0-20240207153957-4fd7d821d952Upgrade to a patched release:
github.com/rancher/apiserver 0.0.0-20240207153957-4fd7d821d952Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
GHSA-wm2r-rp98-8pmhLowExposure of SSH credentials in Rancher/Fleet
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access