PT-2022-10547 · Suse · Suse Rancher

Jonathan Mercier

·

Published

2022-04-01

·

Updated

2024-06-05

·

CVE-2021-36776

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Rancher versions prior to 2.5.10
Description A Improper Access Control issue allows remote attackers to impersonate arbitrary users. This is due to the Steve API proxy not dropping the impersonation header before sending the request to the Kubernetes API, allowing an authenticated user to impersonate any user on a cluster. A malicious user with authenticated access could use this to impersonate another user with administrator access, receiving administrator level access in the cluster.
Recommendations For versions prior to 2.5.10, upgrade to release 2.5.10, 2.6.0, or later versions to resolve the issue. As a temporary workaround, limit access in SUSE Rancher to trusted users.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36776
GHSA-GVH9-XGRQ-R8HW
GO-2024-2771

Affected Products

Suse Rancher