CVE-2023-22651
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
04/05/2023
Last modified:
29/01/2025
Description
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher&#39;s admission Webhook may lead to<br />
the misconfiguration of the Webhook. This component enforces validation<br />
rules and security checks before resources are admitted into the <br />
Kubernetes cluster.<br />
The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.<br />
<br />
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | 2.6.0 (including) | 2.7.2 (including) |
To consult the complete list of CPE names with products and versions, see this page



