—
GO-2024-2930
RKE credentials are stored in the RKE1 Cluster state ConfigMap in github.com/rancher/rke
Quick fix
GO-2024-2930 — github.com/rancher/rke: upgrade to the fixed version with the command below.
go get github.com/rancher/rke@v1.4.19Details
When RKE provisions a cluster, it stores the cluster state in a configmap called "full-cluster-state" inside the "kube-system" namespace of the cluster itself. This cluster state object contains information used to set up the K8s cluster, which may include sensitive data.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/rancher/rke
Introduced in:
1.4.18Fixed in: 1.4.19Fix
go get github.com/rancher/rke@v1.4.19