PT-2025-14372 · Rancher · Rancher

Xavier Duthil

·

Publicado

2025-03-31

·

Atualizado

2025-04-11

·

CVE-2025-23391

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rancher versions prior to v2.8.14 Rancher versions prior to v2.9.8 Rancher versions prior to v2.10.4 Rancher versions prior to v2.11.0
Description A vulnerability has been identified in Rancher where a Restricted Administrator can change the password of Administrators and take over their accounts. This issue arises because a Restricted Administrator should not be allowed to change the password of more privileged users unless they have the Manage Users permissions. The vulnerability can be exploited by abusing elevation control mechanisms, as described in the MITRE ATT&CK Technique T1548.
Recommendations For versions prior to v2.8.14, upgrade to v2.8.14 or later. For versions prior to v2.9.8, upgrade to v2.9.8 or later. For versions prior to v2.10.4, upgrade to v2.10.4 or later. For versions prior to v2.11.0, upgrade to v2.11.0 or later. As a temporary workaround, limit access to Rancher Restricted Admin only to trusted users. Downgrade Restricted Administrators to custom roles with limited permissions.

Correção

LPE

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-03876
CVE-2025-23391
GHSA-8P83-CPFG-FJ3G
GO-2025-3586
OPENSUSE-SU-2025:14970-1

Produtos afetados

Rancher