CVE-2022-43759: Rancher: Privilege escalation via promoted roles
Published Feb 7, 2023
·Updated
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.
Affected Software
2 affected components
SUSE rancher>=2.5.0<2.5.17
SUSE rancher>=2.6.0<2.6.10
Event History
Feb 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-43759.
2
What is the severity of CVE-2022-43759?
The severity of CVE-2022-43759 is high with a severity value of 8.8.
3
Which software versions are affected by CVE-2022-43759?
CVE-2022-43759 affects SUSE Rancher versions prior to 2.5.17 and Rancher versions prior to 2.6.10.
4
What is the CWE of CVE-2022-43759?
The CWE of CVE-2022-43759 is 269.
5
How can I fix CVE-2022-43759?
To fix CVE-2022-43759, update SUSE Rancher to version 2.5.17 or higher, and Rancher to version 2.6.10 or higher.