A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.
History

Wed, 16 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse rancher
Weaknesses CWE-306
CPEs cpe:2.3:a:suse:rancher:-:*:*:*:*:*:*:*
Vendors & Products Suse
Suse rancher
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.
Title Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published: 2024-10-16T08:20:42.467Z

Updated: 2024-10-16T14:44:01.636Z

Reserved: 2023-01-05T10:40:08.605Z

Link: CVE-2023-22650

cve-icon Vulnrichment

Updated: 2024-10-16T14:43:54.172Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-16T09:15:02.957

Modified: 2024-10-16T16:38:14.557

Link: CVE-2023-22650

cve-icon Redhat

No data.