Rancher: Privilege escalation via promoted roles
CVE-2022-43759
7.2HIGH
Summary
An improper privilege management vulnerability in SUSE Rancher allows users with access to utilize the escalate verb on Pod Resource Template Blocks (PRTBs), enabling them to elevate permissions for any promoted resource across any cluster. This presents security risks as unauthorized users could gain higher-level access than intended, potentially compromising the integrity and confidentiality of the system. It is crucial for organizations using affected versions to apply the necessary updates to mitigate potential threats.
Affected Version(s)
Rancher Rancher < 2.5.17
Rancher Rancher < 2.6.10
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved