Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2002 | A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable. |
Github GHSA |
GHSA-9ghh-mmcq-8phc | Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 16 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse rancher |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:suse:rancher:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Suse
Suse rancher |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable. | |
| Title | Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-10-16T14:44:01.636Z
Reserved: 2023-01-05T10:40:08.605Z
Link: CVE-2023-22650
Updated: 2024-10-16T14:43:54.172Z
Status : Awaiting Analysis
Published: 2024-10-16T09:15:02.957
Modified: 2024-10-16T16:38:14.557
Link: CVE-2023-22650
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA