CVE-2023-22650 — Improper Authentication in Rancher
Severity
8.7HIGHNVD
EPSS
0.2%
top 63.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Description
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Packages2 packages
🔴Vulnerability Details
4CVEList▶
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider↗2024-10-16
OSV▶
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider in github.com/rancher/rancher↗2024-06-28
GHSA▶
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider↗2024-06-17
OSV▶
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider↗2024-06-17