Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36974
HistorySep 08, 2022 - 6:08 a.m.

Privilege Escalation

2022-09-0806:08:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
rancher
vulnerability
privilege escalation
permissions
authorization mechanism
software

EPSS

0.001

Percentile

40.5%

github.com/rancher/rancher is vulnerable to privilege escalation. An attacker with permissions to create/edit cluster role template bindings or project role template bindings is able to gain administrator permission in another project in the same cluster or in another project on a different downstream cluster, due to the improper authorization mechanism in the library.

EPSS

0.001

Percentile

40.5%

Related for VERACODE:36974