CVE-2023-22651

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
04/05/2023
Last modified:
29/01/2025

Description

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher&amp;#39;s admission Webhook may lead to<br /> the misconfiguration of the Webhook. This component enforces validation<br /> rules and security checks before resources are admitted into the <br /> Kubernetes cluster.<br /> The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* 2.6.0 (including) 2.7.2 (including)