NA

CVE-2022-31247

Published: 07/09/2022 Updated: 29/03/2023
CVSS v3 Base Score: 9.1 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affects: SUSE Rancher Rancher versions before 2.6.7; Rancher versions before 2.5.16.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse rancher