CVE-2021-25318Incorrect Permission Assignment in Rancher

Severity
8.8HIGHNVD
EPSS
0.1%
top 69.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateJun 10

Description

A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5rancher/rancherRancher2.5.9+1
NVDrancher/rancher2.5.02.5.9+1
Gogithub.com/rancher_rancher2.0.02.4.16+2

🔴Vulnerability Details

4
OSV
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources in github.com/rancher/rancher2024-06-10
OSV
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources2024-04-24
GHSA
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources2024-04-24
CVEList
rancher: API group not properly specified when creating Kubernetes RBAC resources2021-07-15
CVE-2021-25318 — Incorrect Permission Assignment | cvebase