CVE-2023-22648: High severity SUSE rancher vulnerability

Published Jun 1, 2023
·
Updated

A bug has been identified in which permission changes in Azure AD are not reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it.

Impact This issue only affects Rancher instances with Azure AD integration enabled, regardless of the automatically refreshing settings which are enabled by default. The users that obtained a token (or kubeconfig) to access Rancher through the following sessions are affected by this issue: 1) Users using the Rancher UI. 2) Users using kubectl based on a kubeconfig downloaded through the Rancher UI. 3) Tokens created via the Rancher UI Create API Key feature.

Note that the permission caching is persisted even when the Rancher Manager pod is restarted. The only way for a user to get the new permissions is to logout and login again.

Patches Patched versions include releases 2.6.13, 2.7.4 and later versions.

For more information If you have any questions or comments about this advisory:

- Reach out to the SUSE Rancher Security team for security related inquiries. - Open an issue in the Rancher repository. - Verify with our support matrix and product support lifecycle.

Other sources

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

Affected Software

4 affected componentsFixes available
SUSE rancher>=2.6.7<2.6.13
SUSE rancher>=2.7.0<2.7.4
go/github.com/rancher/rancher>=2.7.0<2.7.4
2.7.4
go/github.com/rancher/rancher>=2.6.7<2.6.13
2.6.13

Event History

Jun 1, 2023
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionSeverityWeakness
Data Sourced
01:15 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 3, 2026
Advisory Published
via GitHub·02:48 PM
Data Sourced
via GitHub·02:48 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-22648?

CVE-2023-22648 is an Improper Privilege Management vulnerability in SUSE Rancher that causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI.

2

How does CVE-2023-22648 affect SUSE Rancher?

CVE-2023-22648 affects SUSE Rancher by causing permission changes in Azure AD not to be reflected to users in the Rancher UI.

3

What is the severity of CVE-2023-22648?

CVE-2023-22648 has a severity rating of 8.8 (high).

4

Which versions of SUSE Rancher are affected by CVE-2023-22648?

CVE-2023-22648 affects SUSE Rancher versions 2.6.7 to 2.6.13 and versions 2.7.0 to 2.7.4.

5

Are there any references for CVE-2023-22648?

Yes, you can find references for CVE-2023-22648 at the following links: [1](https://github.com/rancher/rancher/security/advisories/GHSA-vf6j-6739-78m8), [2](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22648).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203