Description
A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
Problem types
CWE-863: Incorrect Authorization
Product status
2.12.0 before 2.12.2
2.11.0 before 2.11.6
2.10.0 before 2.10.10
2.9.0 before 2.9.12
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2024-58260
github.com/...ancher/security/advisories/GHSA-q82v-h4rq-5c86