VYPR
Medium severity6.1NVD Advisory· Published Sep 4, 2019· Updated Jun 17, 2026

CVE-2019-13209

CVE-2019-13209

Description

Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/rancherGo
>= 2.0.0, < 2.0.162.0.16
github.com/rancher/rancherGo
>= 2.1.0, < 2.1.112.1.11
github.com/rancher/rancherGo
>= 2.2.0, < 2.2.52.2.5

Affected products

7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.