Rancher UI has Stored Cross-site Scripting vulnerability in github.com/rancher/rancher

Overview

Source
ID
GO-2025-3391
Aliases
CVE-2024-52281
GHSA-2v2w-8v8c-wcm9

Description

Rancher UI has Stored Cross-site Scripting vulnerability in github.com/rancher/rancher.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/rancher/rancher from v2.9.0 before v2.9.4.

Summary

105
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
7
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
<0.01%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0
Affected
v2.2.10+incompatible
v2.2.9+incompatible
v2.2.8+incompatible
v2.2.7+incompatible
v2.2.6+incompatible
v2.2.5+incompatible
v2.2.4+incompatible
v2.2.3+incompatible
v2.2.2+incompatible
v2.2.1+incompatible
v2.2.0+incompatible
v2.1.14+incompatible
v2.1.13+incompatible
v2.1.12+incompatible
v2.1.9+incompatible
v2.1.8+incompatible
v2.1.7+incompatible
v2.1.6+incompatible
v2.1.5+incompatible
v2.1.4+incompatible
v2.1.3+incompatible
v2.1.2+incompatible
v2.1.1+incompatible
v2.1.0+incompatible
v2.0.9+incompatible
v2.0.8+incompatible
v2.0.7+incompatible
v2.0.6+incompatible
v2.0.5+incompatible
v2.0.4+incompatible
v2.0.3+incompatible
v2.0.2+incompatible
v2.0.1+incompatible
v2.0.0+incompatible