VDB
Sign up
—

GO-2024-2930

RKE credentials are stored in the RKE1 Cluster state ConfigMap in github.com/rancher/rke

Quick fix

GO-2024-2930 — github.com/rancher/rke: upgrade to the fixed version with the command below.

go get github.com/rancher/rke@v1.4.19

Details

When RKE provisions a cluster, it stores the cluster state in a configmap called "full-cluster-state" inside the "kube-system" namespace of the cluster itself. This cluster state object contains information used to set up the K8s cluster, which may include sensitive data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/rancher/rke
Introduced in: 1.4.18Fixed in: 1.4.19
Fixgo get github.com/rancher/rke@v1.4.19

References