High severity8.8NVD Advisory· Published Mar 29, 2017· Updated May 13, 2026
CVE-2017-7297
CVE-2017-7297
Description
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 1.5.0, < 1.5.3 | 1.5.3 |
github.com/rancher/rancherGo | >= 1.4.0, < 1.4.3 | 1.4.3 |
github.com/rancher/rancherGo | >= 1.3.0, < 1.3.5 | 1.3.5 |
github.com/rancher/rancherGo | >= 1.2.0, < 1.2.4 | 1.2.4 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/97180nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-w3x4-9854-95x8ghsaADVISORY
- github.com/rancher/rancher/issues/8296nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-7297ghsaADVISORY
- web.archive.org/web/20200227181556/http://www.securityfocus.com/bid/97180ghsaWEB
News mentions
0No linked articles in our index yet.