Improper Privilege Management in SUSE Rancher Affects Azure AD User Permissions
CVE-2023-22648

8.8HIGH

Key Information:

Vendor
Suse
Status
Vendor
CVE Published:
1 June 2023

Summary

An Improper Privilege Management issue in SUSE Rancher prevents changes in Azure Active Directory (Azure AD) from being accurately reflected in user permissions within the Rancher user interface. This vulnerability allows users who have their permissions downgraded or removed in Azure AD to retain their previous permissions in Rancher while logged in. As a result, users may continue to have unauthorized access to resources within Rancher, even after their group memberships have been altered in Azure AD.

Affected Version(s)

Rancher >= 2.6.7 < 2.6.7

Rancher >= 2.7.0 < 2.7.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/yvespp
.