CVE-2022-31247
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.6.7; Rancher versions prior to 2.5.16.
Published
2022-09-07T09:15:08.747
Last Modified
2024-11-21T07:04:12.897
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 9.1 (CRITICAL)
Weaknesses
-
Type: Secondary
CWE-285
-
Type: Primary
NVD-CWE-Other
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
suse
|
rancher
|
< 2.5.16 |
Yes
|
Application |
suse
|
rancher
|
< 2.6.7 |
Yes
|
References
-
https://bugzilla.suse.com/show_bug.cgi?id=1199730
Exploit, Issue Tracking, Mitigation, Vendor Advisory
([email protected])
-
https://github.com/rancher/rancher/security/advisories/GHSA-6x34-89p7-95wg
Exploit, Mitigation, Third Party Advisory
([email protected])
-
https://bugzilla.suse.com/show_bug.cgi?id=1199730
Exploit, Issue Tracking, Mitigation, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://github.com/rancher/rancher/security/advisories/GHSA-6x34-89p7-95wg
Exploit, Mitigation, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)