Home
MEDIUM: 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HHIGH: 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
2.7.0 (semver) before 2.7.14
affected
2.8.0 (semver) before 2.8.5
affected
Description
A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.
Problem types
CWE-269: Improper Privilege Management
Product status
2.7.0 (semver) before 2.7.14
2.8.0 (semver) before 2.8.5
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32197
github.com/...ancher/security/advisories/GHSA-64jq-m7rq-768h