Vulnerability Description
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Suse | Rancher | >= 2.0.0, <= 2.1.5 |
Related Weaknesses (CWE)
References
- https://forums.rancher.com/c/announcementsVendor Advisory
- https://rancher.com/blog/2019/2019-01-29-explaining-security-vulnerabilities-addVendor Advisory
- https://forums.rancher.com/c/announcementsVendor Advisory
- https://rancher.com/blog/2019/2019-01-29-explaining-security-vulnerabilities-addVendor Advisory
FAQ
What is CVE-2019-6287?
CVE-2019-6287 is a vulnerability with a CVSS score of 8.1 (HIGH). In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
How severe is CVE-2019-6287?
CVE-2019-6287 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6287?
Check the references section above for vendor advisories and patch information. Affected products include: Suse Rancher.