Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
The error results from improper permission handling (CWE-305 — Authentication Bypass by Primary Weakness), which does not properly verify the boundaries of the Project Owner role. A user with this role can exploit the vulnerability to gain permissions that exceed their assigned scope. The attack is possible remotely, without user interaction, however it requires possessing an account with the Project Owner role.
An attacker can obtain unauthorized access to resources and operations reserved for higher-level roles, which may lead to complete takeover of control over the Rancher environment, including managed Kubernetes clusters.
Rancher should be updated to version 2.12.10, 2.13.6, or 2.14.2 (depending on the branch in use). Details are available in the official security advisory from the vendor: https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744
Rancher in versions 2.12 before 2.12.10, 2.13 before 2.13.6, and 2.14 before 2.14.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSUSE Rancher
APPSuse2.12.0 – 2.12.10 (excl.)2.13.0 – 2.13.6 (excl.)2.14.0 – 2.14.2 (excl.)
Related vulnerabilities
SAML authentication replay w Rancher — brak wymuszenia jednorazowego użycia asercji
SUSE Rancher: eskalacja uprawnień przez manipulację Kubernetes secrets
SUSE Rancher – privilege escalation przez błędną konfigurację admission Webhook
SUSE Rancher: przechowywanie poświadczeń w postaci jawnego tekstu
SUSE Rancher: przechowywanie wrażliwych danych w postaci jawnej