A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.
History

Wed, 09 Oct 2024 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 09 Oct 2024 08:45:00 +0000

Type Values Removed Values Added
Description A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4. A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.
Weaknesses CWE-271

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published: 2023-06-01T12:49:35.238Z

Updated: 2024-10-09T08:32:01.217Z

Reserved: 2023-01-05T10:40:08.605Z

Link: CVE-2023-22648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-06-01T13:15:10.553

Modified: 2024-11-21T07:45:07.577

Link: CVE-2023-22648

cve-icon Redhat

No data.