CVE-2024-22036
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Apr 16, 2025
CWE ID 269
Summary
CVE-2024-22036 is a vulnerability affecting Rancher software where a chroot jail escape allows an attacker to gain root access to the Rancher container. In production environments, this could lead to further privilege escalation within the system. For non-production environments using a privileged Docker container, the attacker can also escape the container and gain execution access to the host system. Affected versions of Rancher include those from 2.7.0 before 2.7.16, 2.8.0 before 2.8.9, and 2.9.0 before 2.9.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SUSE/Rancher
Affected Vendors
- SUSE Linux GmbH