VYPR
High severity8.0GHSA Advisory· Published Oct 2, 2025· Updated Apr 15, 2026

CVE-2024-58267

CVE-2024-58267

Description

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/rancherGo
>= 2.12.0, < 2.12.22.12.2
github.com/rancher/rancherGo
>= 2.11.0, < 2.11.62.11.6
github.com/rancher/rancherGo
>= 2.10.0, < 2.10.102.10.10
github.com/rancher/rancherGo
>= 2.9.0, < 2.9.122.9.12

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.