Medium severity6.1NVD Advisory· Published Sep 4, 2019· Updated Jun 17, 2026
CVE-2019-13209
CVE-2019-13209
Description
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.0.0, < 2.0.16 | 2.0.16 |
github.com/rancher/rancherGo | >= 2.1.0, < 2.1.11 | 2.1.11 |
github.com/rancher/rancherGo | >= 2.2.0, < 2.2.5 | 2.2.5 |
Affected products
7- Rancher/Rancherdescription
- osv-coords5 versionspkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fipspkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester-webhookpkg:golang/github.com/rancher/rancher
< 0+ 4 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: >= 2.0.0, < 2.0.16
Patches
Vulnerability mechanics
References
5- forums.rancher.com/c/announcementsnvdRelease NotesVendor Advisory
- forums.rancher.com/t/rancher-release-v2-2-5-addresses-rancher-cve-2019-13209/14801nvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-xhg2-rvm8-w2jhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-13209ghsaADVISORY
- github.com/rancher/rancher/commit/0ddffe484adccb9e37d9432e8e625d8ebbfb0088ghsaWEB
News mentions
0No linked articles in our index yet.