← Back

CVE-2023-22651

nvd nist
Published: May 4, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.

Affected (1)

Products: Suse: Rancher
1 product
Rancher
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.6.0 to 2.7.2

References (4)

Source: meissner@suse.de
Issue TrackingVendor Advisory
Source: meissner@suse.de
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.