Improper Ownership Management Affecting github.com/rancher/rancher/pkg/controllers/managementuser/secret package, versions >=2.8.0-alpha1 <2.9.9-alpha1>=2.10.0-alpha1 <2.10.5-alpha3>=2.11.0-alpha1 <2.11.1-alpha2


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERRANCHERPKGCONTROLLERSMANAGEMENTUSERSECRET-9833923
  • published27 Apr 2025
  • disclosed25 Apr 2025
  • creditUnknown

Introduced: 25 Apr 2025

NewCVE-2024-22031  (opens in a new tab)
CWE-282  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/rancher/pkg/controllers/managementuser/secret to version 2.9.9-alpha1, 2.10.5-alpha3, 2.11.1-alpha2 or higher.

Overview

github.com/rancher/rancher/pkg/controllers/managementuser/secret is a project that provides a container management platform built for organizations that deploy containers in production

Affected versions of this package are vulnerable to Improper Ownership Management for projects, whose namespace defaults to being the project name, regardless of cluster. A user with permission to create a project can escalate privileges to those of a user who owns a project by the same name in a different cluster by creating a project with the same name, thereby gaining access to the other project's resources.

CVSS Base Scores

version 4.0
version 3.1