Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40877
HistoryJun 13, 2023 - 8:24 a.m.

Privilege Escalation

2023-06-1308:24:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
github
rancher
vulnerability
privilege escalation
namespace
update access
project
resources
quota limit
denial of service

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.7%

github.com/rancher/rancher is vulnerable to Privilege Escalation. Users who have update access to a namespace can move it into a project they don’t have access to, giving them access to resources that are only available for that project, allowing access to project-specific resources (such as project secrets). However, resources in the namespace will now be included in the quota limit for the new project, which may cause denial of service conditions.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.7%

Related for VERACODE:40877