Rancher Cross-site Scripting Vulnerability

Overview

Source
ID
GHSA-6m8r-jh89-rq7h
Aliases
CVE-2021-25313

Description

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.

Summary

105
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
7
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
<0.01%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 2.5.0, Fixed: 2.5.6, Introduced: 2.4.0, Fixed: 2.4.14, Introduced: 0, Fixed: 2.3.11
Affected
v2.2.10+incompatible
v2.2.9+incompatible
v2.2.8+incompatible
v2.2.7+incompatible
v2.2.6+incompatible
v2.2.5+incompatible
v2.2.4+incompatible
v2.2.3+incompatible
v2.2.2+incompatible
v2.2.1+incompatible
v2.2.0+incompatible
v2.1.14+incompatible
v2.1.13+incompatible
v2.1.12+incompatible
v2.1.9+incompatible
v2.1.8+incompatible
v2.1.7+incompatible
v2.1.6+incompatible
v2.1.5+incompatible
v2.1.4+incompatible
v2.1.3+incompatible
v2.1.2+incompatible
v2.1.1+incompatible
v2.1.0+incompatible
v2.0.9+incompatible
v2.0.8+incompatible
v2.0.7+incompatible
v2.0.6+incompatible
v2.0.5+incompatible
v2.0.4+incompatible
v2.0.3+incompatible
v2.0.2+incompatible
v2.0.1+incompatible
v2.0.0+incompatible