CVE-2022-21953: Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-21953.
What is the severity of CVE-2022-21953?
CVE-2022-21953 has a severity of 8.8, which is considered high.
What is the affected software for CVE-2022-21953?
The affected software for CVE-2022-21953 is SUSE Rancher versions prior to 2.5.17, Rancher versions prior to 2.6.10, and Rancher versions prior to 2.7.1.
How does the vulnerability CVE-2022-21953 manifest?
The vulnerability CVE-2022-21953 allows an authenticated user to create an unauthorized shell pod and gain kubectl access in the local cluster.
Is there a fix available for CVE-2022-21953?
Yes, please update your SUSE Rancher version to 2.5.17, 2.6.10, or 2.7.1 to fix CVE-2022-21953.