An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1
Published Jul 30, 2019
9.8
CRITICALCVSS 3.0
EPSS 1.60%
Description
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
github.com/rancher/rancher
Go
Introduced 2.0.0+incompatible Fixed 2.2.2+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rancher/rancher | 2.0.0+incompatible | 2.2.2+incompatible |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.60% (0.01604) | 74.96th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.60% (0.01604) | 74.75th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.34% (0.00341) | 71.73th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.34% (0.00341) | 70.65th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.34% (0.00341) | 66.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v1 |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Jan 5, 2022 | 0.62% (0.00624) | 46.35th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (6)
- https://forums.rancher.com/c/announcements x_refsource_MISCRelease NotesVendor Advisory
- https://forums.rancher.com/t/rancher-release-v2-2-2-addresses-rancher-cve-2019-11202-and-stability-issues/13977
- https://github.com/advisories/GHSA-xh8x-j8h3-m5ph Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11202
- https://pkg.go.dev/vuln/GO-2024-2784
- https://rancher.com/docs/rancher/v2.x/en/security/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://forums.rancher.com/c/announcements | x_refsource_MISCRelease NotesVendor Advisory | |
| https://forums.rancher.com/t/rancher-release-v2-2-2-addresses-rancher-cve-2019-11202-and-stability-issues/13977 | ||
| https://github.com/advisories/GHSA-xh8x-j8h3-m5ph | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11202 | ||
| https://pkg.go.dev/vuln/GO-2024-2784 | ||
| https://rancher.com/docs/rancher/v2.x/en/security/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.