Authorization Flaw in Rancher Affects Namespace Management by Users
CVE-2020-10676

Currently unrated

Key Information:

Vendor

Rancher

Status
Vendor
CVE Published:
12 December 2023

What is CVE-2020-10676?

In specific versions of Rancher, an authorization flaw permits users with limited access to a namespace to move that namespace to a different project. This oversight compromises the intended security model, enabling unauthorized project manipulation. It's crucial for users to apply patches to mitigate potential risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.