A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive *
permissions for core namespaces. This can lead to someone being capable
of accessing, creating, updating, or deleting a namespace in the
project.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0611 A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project.
Github GHSA Github GHSA GHSA-c85r-fwc7-45vc Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0008}

epss

{'score': 0.00082}


Wed, 16 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Rancher
Rancher rancher
CPEs cpe:2.3:a:rancher:rancher:*:*:*:*:*:*:*:*
Vendors & Products Rancher
Rancher rancher
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project.
Title Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2024-10-16T17:25:32.070Z

Reserved: 2023-05-04T08:30:59.322Z

Link: CVE-2023-32194

cve-icon Vulnrichment

Updated: 2024-10-16T16:04:57.754Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-16T13:15:12.787

Modified: 2024-10-16T16:38:14.557

Link: CVE-2023-32194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.