← voltar
CVE-2022-31247

Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

CVSS 9.1 CRITICALEPSS 0.8%CWE-285
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.6.7; Rancher versions prior to 2.5.16.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
SUSE · Rancher

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →