{"id":"CVE-2019-13209","aliases":["GHSA-xhg2-rvm8-w2jh","GO-2022-0755"],"url":"https://o3.security/vulnerability/CVE-2019-13209","summary":"Rancher Vulnerable to Cross-site Request Forgery (CSRF)","details":"Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.","published":"2019-09-04T14:15:11.200Z","modified":"2026-08-07T14:49:02.987755Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/rancher/rancher","fixedVersion":"2.0.16"},{"ecosystem":"Go","name":"github.com/rancher/rancher","fixedVersion":"2.1.11"},{"ecosystem":"Go","name":"github.com/rancher/rancher","fixedVersion":"2.2.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://forums.rancher.com/c/announcements"},{"type":"ADVISORY","url":"https://forums.rancher.com/t/rancher-release-v2-2-5-addresses-rancher-cve-2019-13209/14801"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:02.987755Z"}}