Description
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
Problem types
CWE-284: Improper Access Control
Product status
2.8.0 (semver) before 2.8.13
2.9.0 (semver) before 2.9.7
2.10.0 (semver) before 2.10.3
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23389
github.com/...ancher/security/advisories/GHSA-mq23-vvg7-xfm4