CVE-2023-32199

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/10/2025
Last modified:
30/10/2025

Description

A vulnerability has been identified within Rancher <br /> Manager, where after removing a custom GlobalRole that gives <br /> administrative access or the corresponding binding, the user still <br /> retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs