GMS-2023-140: Rancher cattle-token is predictable
An issue was discovered in Rancher versions up to and including 2.6.9 and 2.7.0, where the cattle-token
secret, used by the cattle-cluster-agent
, is predictable. Even after the token is regenerated, it will have the same value. This issue is not present in Rancher 2.5 releases.
References
Detect and mitigate GMS-2023-140 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →