Back to overview

CVE-2023-22647

CRITICAL
9.9
CVSS 3.1
Description
An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. When this operation was followed-up by other specially crafted commands, it could result in the user gaining access to tokens belonging to service accounts in the local cluster. This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

Metadata

CVE ID
CVE-2023-22647
State
PUBLISHED
Assigner
suse
Reserved
2023-01-05 10:40 UTC
Published
2023-06-01 12:52 UTC
Last updated
2025-01-09 17:00 UTC
Primary CWE
CWE-267
CWE-267: Privilege Defined With Unsafe Actions
Vendor / Product
SUSE / Rancher
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SUSE Rancher >= 2.6.0 < < 2.6.13, >= 2.7.0 < < 2.7.4
Weakness (CWE)
CWESourceDescription
CWE-267 cna CWE-267: Privilege Defined With Unsafe Actions
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview