Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39093
HistoryFeb 03, 2023 - 5:51 a.m.

Improper Access Control

2023-02-0305:51:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
vulnerability
rancher
authenticated attacker
shell pod
kubectl access

EPSS

0.001

Percentile

37.5%

github.com/rancher/rancher is vulnerable to Improper Access Control. The vulnerability exists in proxy.go where an authorization logic flaw allows an authenticated attacker on any downstream cluster to open a shell pod in the Rancher local cluster or have limited kubectl access to the pod.

EPSS

0.001

Percentile

37.5%

Related for VERACODE:39093