Improper Authorization Affecting github.com/rancher/rancher/pkg/api/steve/disallow Open this link in a new tab package, versions <2.5.10 >=2.6.0-rc1 <2.6.0


0.0
high
  • Attack Complexity

    Low

  • Confidentiality

    High

  • Integrity

    High

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-GOLANG-GITHUBCOMRANCHERRANCHERPKGAPISTEVEDISALLOW-2869158

  • published

    15 Jun 2022

  • disclosed

    13 Jun 2022

  • credit

    Unknown

How to fix?

Upgrade github.com/rancher/rancher/pkg/api/steve/disallow to version 2.5.10, 2.6.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization which allows an authenticated user to impersonate any user on a cluster through the Steve API proxy, without requiring knowledge of the impersonated user's credentials.