Back to overview

CVE-2023-22651

CRITICAL
9.9
CVSS 3.1
Description
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.

Metadata

CVE ID
CVE-2023-22651
State
PUBLISHED
Assigner
suse
Reserved
2023-01-05 10:40 UTC
Published
2023-05-04 07:53 UTC
Last updated
2025-01-29 16:49 UTC
Primary CWE
CWE-269
CWE-269 Improper Privilege Management
Vendor / Product
SUSE / Rancher
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SUSE Rancher 2.6.0 ≤ 2.7.2, 2.7.3
Weakness (CWE)
CWESourceDescription
CWE-269 cna CWE-269 Improper Privilege Management
CWE-276 adp CWE-276 Incorrect Default Permissions
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview