Self-Signed CA Certificate Vulnerability in Rancher Manager by Rancher
CVE-2025-67601
What is CVE-2025-67601?
A vulnerability has been discovered in Rancher Manager that arises when users utilize self-signed CA certificates without properly configuring the Rancher CLI. Specifically, passing the -skip-verify flag during login without the -cacert flag leads to the CLI making attempts to retrieve CA certificates from the settings, potentially exposing the system to security risks. It is crucial for users to ensure that the appropriate flags are implemented to safeguard against unauthorized access and other associated threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rancher 0 < 0.0.0-20260129092249-bb0625fd1896
rancher 2.13.0 < 2.13.2
rancher 2.12.0 < 2.12.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved