PT-2022-10551 · Suse · Suse Rancher
Guilherme Macedo
·
Published
2022-05-02
·
Updated
2022-05-09
·
CVE-2021-36784
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SUSE Rancher versions prior to 2.5.13
SUSE Rancher versions prior to 2.6.4
Description
A Improper Privilege Management issue in SUSE Rancher allows users with the
restricted-admin role to escalate to full admin. This affects customers who utilize non-admin users that are able to create or edit Global Roles. The vulnerability can be exploited by users with create or update permissions on Global Roles, allowing them to escalate their permissions or those of another user to admin-level permissions.Recommendations
For SUSE Rancher versions prior to 2.5.13, update to version 2.5.13 or later.
For SUSE Rancher versions prior to 2.6.4, update to version 2.6.4 or later.
As a temporary workaround, limit access in Rancher to trusted users.
Review the roles and users created by non-admin users with create or edit permissions on Global Roles for possible privilege escalations.
Fix
Improper Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Rancher