Rancher: Privilege escalation via promoted roles
CVE-2022-43759
What is CVE-2022-43759?
An improper privilege management vulnerability in SUSE Rancher allows users with access to utilize the escalate verb on Pod Resource Template Blocks (PRTBs), enabling them to elevate permissions for any promoted resource across any cluster. This presents security risks as unauthorized users could gain higher-level access than intended, potentially compromising the integrity and confidentiality of the system. It is crucial for organizations using affected versions to apply the necessary updates to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rancher Rancher < 2.5.17
Rancher Rancher < 2.6.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved