a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HRancher
APPRancher< 2.4.182.5.0 – 2.5.12 (excl.)2.6.0 – 2.6.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-25320CRITICAL9.9PL ✓same product
Rancher: nieprawidłowa kontrola dostępu do poświadczeń dostawców chmury
CVE-2021-36776HIGH8.8same product
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. T...
CVE-2021-25318HIGH8.8same product
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster t...
CVE-2021-31999HIGH8.8same product
A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to ...