Improper Privilege Management in SUSE Rancher Affects Kubernetes Secrets
CVE-2023-22647
What is CVE-2023-22647?
An Improper Privilege Management vulnerability in SUSE Rancher enables standard users to exploit their permissions for manipulating Kubernetes secrets within the local cluster. This flaw permits users to delete secrets while maintaining read-level permissions for those secrets. If exploited alongside other specially crafted commands, this could result in unauthorized access to sensitive tokens associated with service accounts in the local cluster, potentially compromising the integrity of the Kubernetes environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rancher >= 2.6.0 < 2.6.0
Rancher >= 2.7.0 < 2.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved