Vulnerability Description
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32199
- https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59
FAQ
What is CVE-2023-32199?
CVE-2023-32199 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to ...
How severe is CVE-2023-32199?
CVE-2023-32199 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32199?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.