{"schema_version":"1.9.0","id":"CVE-2024-22030","published":"2024-10-16T13:24:06.944Z","modified":"2026-08-12T03:51:33.143141171Z","aliases":["GHSA-h4h5-9833-v2p4","GO-2024-3161"],"related":["CGA-chgx-gm56-m266","SUSE-SU-2024:3911-1","openSUSE-SU-2024:0350-1","openSUSE-SU-2024:14447-1"],"summary":"Rancher agents can be hijacked by taking over the Rancher Server URL","details":"A vulnerability has been identified within Rancher that can be exploited\n in narrow circumstances through a man-in-the-middle (MITM) attack. An \nattacker would need to have control of an expired domain or execute a \nDNS spoofing/hijacking attack against the domain to exploit this \nvulnerability. The targeted domain is the one used as the Rancher URL.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rancher/rancher","events":[{"introduced":"ce9a7aea4b13fed7acd02cc32667b2ae72f98f5a"},{"fixed":"c1c524865a9fb4d72eed574a16f53c31e5a5ae31"},{"introduced":"72f58378bf03122a9651c9bd3b4c143a57e8fdaa"},{"fixed":"e61d915fb7af485842e990e7d6e5a8813fe65844"},{"introduced":"9e0cc54e7e3a924cf0ed5c5d4db0a6e53805c75e"},{"fixed":"3da2ae0cabd11aa3af8bc463f5e5e74a3f156c71"}],"database_specific":{"extracted_events":[{"introduced":"2.7.0"},{"fixed":"2.7.15"},{"introduced":"2.8.0"},{"fixed":"2.8.8"},{"introduced":"2.9.0"},{"fixed":"2.9.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.8.6-alpha6","v2.8.6","v2.9.2-rc1","v2.8.8-rc1","v2.9.2-alpha7","v2.9.2-alpha6","v2.8.8-alpha2","v2.9.2-alpha5","v2.9.2-alpha4","v2.9.2-alpha3","v2.8.8-alpha1","v2.9.2-alpha2","v2.9.2-alpha1","v2.8.7-rc10","v2.8.7","v2.9.1","v2.9.1-rc6","v2.8.7-rc9","v2.9.1-rc5","v2.9.1-rc4","v2.8.7-rc8","v2.8.7-rc7","v2.9.1-alpha2","v2.8.7-rc6","v2.9.1-rc3","v2.8.7-rc5","v2.8.7-rc4","v2.8.7-rc3","v2.9.1-rc2","v2.9.1-rc1","v2.8.7-rc2","v2.8.7-rc1","v2.9.1-alpha1","v2.9.0-rc6","v2.9.0","v2.7.15-rc2","v2.8.6-alpha5","v2.8.6-rc4","v2.8.6-rc3","v2.8.6-rc2","v2.8.6-rc1","v2.7.15-rc1","v2.7.15-alpha5","v2.7.15-alpha4","v2.7.15-alpha3","v2.8.6-alpha4","v2.7.15-alpha2","v2.7.15-alpha1","v2.8.6-alpha3","v2.7.14-rc3","v2.7.14","v2.8.6-alpha2","v2.8.4-rc5","v2.8.4","v2.7.14-rc2","v2.7.14-rc1","v2.7.13-rc5","v2.7.13","v2.8.6-alpha1","v2.8.3-rc8","v2.8.3","v2.8.4-rc4","v2.7.13-rc4","v2.8.4-rc3","v2.7.13-rc3","v2.8.4-rc2","v2.8.4-rc1","v2.7.13-rc2","v2.7.13-rc1","v2.8.4-alpha1","v2.7.13-alpha1","v2.8.3-rc7","v2.7.12-rc3","v2.7.12","v2.8.3-rc6","v2.8.3-rc5","v2.7.12-rc2","v2.7.12-alpha2","v2.7.12-alpha1","v2.8.3-rc4","v2.7.12-rc1","v2.8.3-rc3","v2.8.3-rc2","v2.8.3-rc1","v2.8.3-alpha2","v2.8.3-alpha1","v2.7.5","v2.8.0-rc5","v2.8.0","v2.7.8-rc1","v2.7.8","v2.7.7-rc7","v2.7.7","v2.7.7-rc6","v2.7.7-rc5","v2.7.7-rc3","v2.7.7-rc4","v2.7.7-rc2","v2.7.7-rc1","v2.7.5-rc6","v2.7.5-rc5","v2.7.5-rc4","v2.7.5-rc3","v2.7.5-rc2","v2.7.5-rc1","v2.7.2-rc9","v2.7.2-rc10","v2.7.2","v2.7.2-rc8","v2.7.2-rc7","v2.7.2-rc6","v2.7.2-rc5","v2.7.2-rc4","v2.7.2-rc3","v2.7.2-rc2","v2.7.0-novkdm","v2.7.0","v2.7.2-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-22030.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/22xxx/CVE-2024-22030.json"},{"type":"ADVISORY","url":"https://github.com/rancher/rancher/security/advisories/GHSA-h4h5-9833-v2p4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22030"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22030"}],"database_specific":{"cna_assigner":"suse","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/22xxx/CVE-2024-22030.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}