Self-Signed CA Certificate Vulnerability in Rancher Manager by Rancher
CVE-2025-67601
8.3HIGH
What is CVE-2025-67601?
A vulnerability has been discovered in Rancher Manager that arises when users utilize self-signed CA certificates without properly configuring the Rancher CLI. Specifically, passing the -skip-verify flag during login without the -cacert flag leads to the CLI making attempts to retrieve CA certificates from the settings, potentially exposing the system to security risks. It is crucial for users to ensure that the appropriate flags are implemented to safeguard against unauthorized access and other associated threats.
Affected Version(s)
rancher 0 < 0.0.0-20260129092249-bb0625fd1896
rancher 2.13.0 < 2.13.2
rancher 2.12.0 < 2.12.6