CVE-2023-32196
- EPSS 0.04%
- Veröffentlicht 16.10.2024 13:15:13
- Zuletzt bearbeitet 16.10.2024 16:38:14
A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.
CVE-2023-32194
- EPSS 0.09%
- Veröffentlicht 16.10.2024 13:15:12
- Zuletzt bearbeitet 16.10.2024 16:38:14
A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessin...
CVE-2021-36775
- EPSS 0.28%
- Veröffentlicht 04.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:04
a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6....
CVE-2021-36776
- EPSS 0.53%
- Veröffentlicht 04.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:04
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.
CVE-2021-25320
- EPSS 0.2%
- Veröffentlicht 15.07.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:44
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks T...
CVE-2021-31999
- EPSS 0.38%
- Veröffentlicht 15.07.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:41
A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" or "Impersonate-Group" headers. This issue affects: Rancher versions pr...
CVE-2021-25318
- EPSS 0.12%
- Veröffentlicht 15.07.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:44
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.