First published: Tue Feb 07 2023(Updated: )
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Rancher | >=2.5.0<2.5.17 | |
SUSE Rancher | >=2.6.0<2.6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-43759.
The severity of CVE-2022-43759 is high with a severity value of 8.8.
CVE-2022-43759 affects SUSE Rancher versions prior to 2.5.17 and Rancher versions prior to 2.6.10.
The CWE of CVE-2022-43759 is 269.
To fix CVE-2022-43759, update SUSE Rancher to version 2.5.17 or higher, and Rancher to version 2.6.10 or higher.