CVE-2020-10676Incorrect Authorization in Rancher Rancher

Severity
8.8HIGHNVD
EPSS
0.2%
top 59.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDsuse/rancher2.0.02.6.13+1
Gogithub.com/rancher_rancher2.6.02.6.13+1

🔴Vulnerability Details

3
CVEList
CVE-2020-10676: In Rancher 22023-12-12
GHSA
Rancher users retain access after moving namespaces into projects they don't have access to2023-06-06
OSV
Rancher users retain access after moving namespaces into projects they don't have access to2023-06-06
CVE-2020-10676 — Incorrect Authorization | cvebase