CVE-2021-4200: Write access to the Catalog for any user when restricted-admin role is enabled
Published May 2, 2022
·Updated
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
Affected Software
2 affected components
SUSE rancher<2.5.13
SUSE rancher>=2.6.0<2.6.4
Event History
May 2, 2022
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-4200.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for...'.
3
What is the severity of CVE-2021-4200?
The severity of CVE-2021-4200 is medium.
4
Which versions of SUSE Rancher are affected by CVE-2021-4200?
SUSE Rancher versions prior to 2.5.13 and Rancher versions prior to 2.6.4 are affected by CVE-2021-4200.
5
How can I fix the CVE-2021-4200 vulnerability?
To fix the CVE-2021-4200 vulnerability, update SUSE Rancher to version 2.5.13 or higher and Rancher to version 2.6.4 or higher.