PT-2022-4713 · Suse · Suse Rancher

Rmweir

·

Published

2022-09-07

·

Updated

2026-03-03

·

CVE-2022-31247

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Rancher versions prior to 2.6.7 SUSE Rancher versions prior to 2.5.16
Description The issue is related to an Improper Authorization vulnerability in SUSE Rancher. It allows any user with permissions to create or edit cluster role template bindings or project role template bindings, such as cluster-owner or project-owner, to gain owner permission in another project within the same cluster or in a different project on a downstream cluster. This can potentially lead to privilege escalation.
Recommendations For versions prior to 2.6.7, update to version 2.6.7 or later. For versions prior to 2.5.16, update to version 2.5.16 or later.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-05604
CVE-2022-31247
GHSA-6X34-89P7-95WG

Affected Products

Suse Rancher