Rancher Vulnerability: Unauthorized Access via Deleted Users
CVE-2023-22650
8.8HIGH
What is CVE-2023-22650?
A user management vulnerability has been discovered in Rancher, where the platform fails to automatically revoke access for users who have been deleted or disabled in the configured authentication provider. This oversight means that tokens associated with these users remain active, potentially allowing unauthorized access to resources. As a result, organizations using Rancher are at risk of lingering access through obsolete user credentials, which may not be addressed by the usual user management processes.
Affected Version(s)
rancher 2.7.0 < 2.7.14
rancher 2.8.0 < 2.8.5