Database/Container, Kubernetes & orchestration
Rancher: CLI login with -skip-verify and no --cacert silently accepts any certificate
CVSS 8.3CVE-2025-67601Container, Kubernetes & orchestrationcurated
Impact
CLI login with -skip-verify and no --cacert silently accepts any certificate; MITM on the management API
Who can reach it
Unauthenticated network in a MITM position
What to do
Upgrade Rancher CLI; ban -skip-verify in runbooks
References
Related entries
- Rancher: OS command injection through an untrusted Helm catalog URLCVE-2022-43758 · RancherHigh
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessCVE-2022-21953 · RancherHigh
- Rancher: restricted-admin role escalates to full adminCVE-2021-36784 · RancherHigh
- Rancher: Insufficient entropy means a leaked cattle-token stays usable after rotationCVE-2022-43755 · RancherHigh
- Rancher: Cluster owners, members and even base users retrieve plaintext credentials via the Kubernetes APICVE-2021-36782 · RancherCritical
- Rancher: Insufficiently protected credentials let project members read passwords and API tokensCVE-2021-36783 · RancherCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.