Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.4epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login.
This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Affected products
SUSE · rancher