First published: Fri Apr 15 2022(Updated: )
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Rancher | <2.5.13 | |
SUSE Rancher | >=2.6.0<2.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-4200.
The title of this vulnerability is 'A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for...'.
The severity of CVE-2021-4200 is medium.
SUSE Rancher versions prior to 2.5.13 and Rancher versions prior to 2.6.4 are affected by CVE-2021-4200.
To fix the CVE-2021-4200 vulnerability, update SUSE Rancher to version 2.5.13 or higher and Rancher to version 2.6.4 or higher.