PT-2022-10546 · Suse · Suse Rancher

Jonathan Mercier

·

Published

2022-04-01

·

Updated

2024-06-05

·

CVE-2021-36775

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Rancher versions prior to 2.4.18 SUSE Rancher versions prior to 2.5.12 SUSE Rancher versions prior to 2.6.3
Description An Improper Access Control issue in SUSE Rancher allows users to retain privileges that should have been revoked. This occurs due to an incomplete authorization logic check when removing a Project Role associated with a group from a project, resulting in the bindings that grant access to cluster-scoped resources not being deleted. A user who is a member of an affected group with authenticated access to Rancher could exploit this to access resources they should no longer have access to. The exposure level depends on the original permission level granted to the affected project role.
Recommendations For SUSE Rancher versions prior to 2.4.18, update to version 2.4.18 or later. For SUSE Rancher versions prior to 2.5.12, update to version 2.5.12 or later. For SUSE Rancher versions prior to 2.6.3, update to version 2.6.3 or later. As a temporary workaround, limit access in Rancher to trusted users.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36775
GHSA-28G7-896H-695V
GO-2024-2760

Affected Products

Suse Rancher