A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute arbitrary JavaScript code in the victim browser
https://github.com/rancher/apiserver/security/advisories/GHSA-833m-37f7-jq55