The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/rancher/rancher/pkg/auth/providers/github to version 2.13.6-alpha5, 2.14.2-alpha5, 2.15.0-alpha5 or higher.
Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm in the authentication provider's team membership evaluation process. An attacker can gain unauthorized access to resources or permissions assigned to other teams within the same organization by authenticating with a valid account that is a member of any team in the organization. This is only exploitable if the GitHub App authentication provider is enabled and configured for the target organization, the attacker is a member of at least one team, and another team is explicitly mapped to RBAC roles or allowlists.
This vulnerability can be mitigated by disabling the GitHub App authentication provider, switching to an alternative authentication provider (such as GitHub OAuth), removing or restricting team-based group principals from allowed principalIds, auditing and temporarily removing RBAC bindings that reference GitHub App team principals, or disabling provider refresh and cleaning up inflated group membership for users.