PT-2022-10551 · Suse · Suse Rancher

Guilherme Macedo

·

Published

2022-05-02

·

Updated

2022-05-09

·

CVE-2021-36784

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Rancher versions prior to 2.5.13 SUSE Rancher versions prior to 2.6.4
Description A Improper Privilege Management issue in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This affects customers who utilize non-admin users that are able to create or edit Global Roles. The vulnerability can be exploited by users with create or update permissions on Global Roles, allowing them to escalate their permissions or those of another user to admin-level permissions.
Recommendations For SUSE Rancher versions prior to 2.5.13, update to version 2.5.13 or later. For SUSE Rancher versions prior to 2.6.4, update to version 2.6.4 or later. As a temporary workaround, limit access in Rancher to trusted users. Review the roles and users created by non-admin users with create or edit permissions on Global Roles for possible privilege escalations.

Fix

Improper Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36784
GHSA-JWVR-VV7P-GPWQ

Affected Products

Suse Rancher