

If you're installing Rancher for the first time, your environment must fulfill the installation requirements.For more information, see CVE-2023-22648.įor more details, see the Security Advisories and CVEs page in Rancher's documentation page or in Rancher's GitHub repo. This caused users to retain their previous permissions in Rancher, even if they changed groups on Azure AD. Fixed an issue where changing a user's permissions in Azure AD wasn't reflected for users while they were logged in to the Rancher UI.For more information, see CVE-2023-22647. Fixed an issue that enabled Standard users or above to elevate their permissions to Administrator in the local cluster.For more information, see CVE-2022-43760. This would allow an attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victim. Fixed an issue where cross-site scripting (XSS) could allow a malicious user to inject code executed within another user's browser.For more information, see CVE-2020-10676. Fixed an issue where users with update privileges on a namespace could move that namespace into a project they didn't have access to.This release addresses the following Rancher security issues: Rancher v2.7.4 is a security release to address the following issues: Security Fixes for Rancher Vulnerabilities It is important to review the Install/Upgrade Notes below before upgrading to any Rancher version. ChartDefaultBranch: dev-v2.7 ( pkg/settings/setting.go).KDMBranch: dev-v2.7 ( pkg/settings/setting.go).CATTLE_KDM_BRANCH: dev-v2.7 ( Dockerfile.dapper).CATTLE_KDM_BRANCH: dev-v2.7 ( package/Dockerfile).CHART_DEFAULT_BRANCH: dev-v2.7 ( package/Dockerfile).

SYSTEM_CHART_DEFAULT_BRANCH: dev-v2.7 ( package/Dockerfile).CHART_DEFAULT_BRANCH: dev-v2.7 ( scripts/package-env).SYSTEM_CHART_DEFAULT_BRANCH: dev-v2.7 ( scripts/package-env).RKE v1.4.6-rc3 Min version components with -rcĬSP_ADAPTER_MIN_VERSION 2.0.2+up2.0.2-rc2įLEET_MIN_VERSION 102.1.0+up0.7.0-rc.3 RKE Kubernetes versions

Rancher/system-agent v0.3.3-rc4-suc Components with -rc

Rancher/backup-restore-operator v3.1.1-rc9
