VYPR
High severity8.0NVD Advisory· Published Oct 16, 2024· Updated Apr 15, 2026

CVE-2024-22030

CVE-2024-22030

Description

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/rancherGo
>= 2.7.0, < 2.7.152.7.15
github.com/rancher/rancherGo
>= 2.8.0, < 2.8.82.8.8
github.com/rancher/rancherGo
>= 2.9.0, < 2.9.22.9.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.