Improper Preservation of Permissions Affecting github.com/rancher/rancher/pkg/rbac package, versions <2.11.7-alpha2>=2.12.0 <2.12.3-alpha2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERRANCHERPKGRBAC-13720740
  • published26 Oct 2025
  • disclosed24 Oct 2025
  • creditUnknown

Introduced: 24 Oct 2025

NewCVE-2023-32199  (opens in a new tab)
CWE-281  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/rancher/pkg/rbac to version 2.11.7-alpha2, 2.12.3-alpha2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Preservation of Permissions due to the improper removal of ClusterRoleBinding objects when a custom administrative global role or its binding is deleted. An attacker can retain unauthorized access to clusters by leveraging orphaned ClusterRoleBinding entries that persist after the intended permissions have been revoked.

Workaround

This vulnerability can be mitigated by manually identifying and removing orphaned ClusterRoleBindings that are annotated with 'authz.cluster.cattle.io/admin-globalrole-missing=true'.

CVSS Base Scores

version 4.0
version 3.1