Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-22648
HistoryJun 01, 2023 - 1:15 p.m.

Privilege escalation

2023-06-0113:15:00
PRIOn knowledge base
www.prio-n.com
6
suse rancher
azure ad
privilege management
permission changes

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.3%

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users
while they are logged in the Rancher UI. This would cause the users to
retain their previous permissions in Rancher, even if they change groups
on Azure AD, for example, to a lower privileged group, or are removed
from a group, thus retaining their access to Rancher instead of losing
it.
This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.3%

Related for PRION:CVE-2023-22648