We found results for “”
CVE-2023-22650
Good to know:
Date: October 16, 2024
Rancher 2.7 before 2.7.14 and 2.8 before 2.8.5 does not automatically clean up a user deleted from the configured Authentication Provider. This issue may lead to an adversary gaining unauthorized access, as the user’s access privileges may still be active within Rancher even though they are no longer valid on the configured AP.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |