Listen to this Post
How the CVE Works:
This vulnerability in Rancher Manager exposes sensitive data through its audit logs. It operates via two primary leakage paths. First, when Kubernetes Secrets are created using the `stringData` field, the plaintext secret value is stored in the `kubectl.kubernetes.io/last-applied-configuration` annotation. Rancher’s audit logging mechanism captures both the request and response bodies, including this annotation, without redacting the embedded secret. Second, during the import or creation of downstream clusters, the audit logs record complete cluster registration manifests. These logs contain non-expiring cluster import URLs, full `kubectl apply` commands with registration tokens, and the token values themselves. Any user or attacker with access to the audit log storage can extract these secrets and tokens. The registration tokens remain valid until manually revoked, allowing for unauthorized node registration and full cluster access, facilitating lateral movement within the environment.
Platform: Rancher Manager
Version: < v2.12.3
Vulnerability: Information Disclosure
Severity: Critical
date: 2024-03-27
Prediction: Patch Available
What Undercode Say:
grep -r "kubectl.kubernetes.io/last-applied-configuration" /var/log/rancher/
curl -k -H "Authorization: Bearer <token>" https://rancher.example.com/v3/import/
kubectl get secrets -o jsonpath='{.items[].metadata.annotations}' | jq .
How Exploit:
Access audit logs.
Extract secrets from annotations.
Harvest cluster registration tokens.
Execute `kubectl apply` with stolen token.
Gain unauthorized cluster access.
Protection from this CVE
Upgrade to v2.12.3.
Implement strict AuditPolicies.
Restrict log access.
Avoid using `stringData`.
Manually rotate tokens.
Impact:
Plaintext secret recovery.
Unauthorized cluster registration.
Lateral movement potential.
Full cluster compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

