A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0388 | A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10. |
Github GHSA |
GHSA-7m72-mh5r-6j3r | Privilege escalation in project role template binding (PRTB) and -promoted roles |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1205293 |
|
History
Tue, 25 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-03-25T15:18:24.059Z
Reserved: 2022-10-26T00:00:00.000Z
Link: CVE-2022-43759
Updated: 2024-08-03T13:40:06.453Z
Status : Modified
Published: 2023-02-07T13:15:09.967
Modified: 2024-11-21T07:27:10.440
Link: CVE-2022-43759
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA