Improper Privilege Management Affecting github.com/rancher/rancher package, versions >=2.6.7 <2.6.13 >=2.7.0 <2.7.4
Threat Intelligence
EPSS
0.12% (47th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMRANCHERRANCHER-5664729
- published 2 Jun 2023
- disclosed 2 Jun 2023
- credit @yvespp
Introduced: 2 Jun 2023
CVE-2023-22648 Open this link in a new tabHow to fix?
Upgrade github.com/rancher/rancher
to version 2.6.13, 2.7.4 or higher.
Overview
Affected versions of this package are vulnerable to Improper Privilege Management causing permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it.
References
CVSS Scores
version 3.1