-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the Steve API proxy not sanitizing impersonation headers before proxying requests to Kubernetes. The primary function responsible for handling HTTP requests in the Steve API proxy is Handler.ServeHTTP in pkg/steve/proxy/proxy.go. Since the flaw explicitly involves improper header handling during proxying, this function is the logical point where the header sanitization should occur. The lack of header filtering here would directly enable the privilege escalation described. While explicit code isn't provided, the component structure and vulnerability mechanics strongly implicate this function.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/rancher/rancher | go | >= 2.5.0, <= 2.5.9 | 2.5.10 |
Ongoing coverage of React2Shell