Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
rancher: API group not properly specified when creating Kubernetes RBAC resources
Vulnerability Description
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Rancher Labs Rancher 授权问题漏洞
Vulnerability Description
Rancher Labs Rancher是美国Rancher Labs公司的一套开源的企业级容器管理平台。 Rancher 存在授权问题漏洞,该漏洞源于产品对于关键资源的管理缺少有效的权限管理,攻击者可通过该漏洞访问不该访问的资源。以下产品及版本受到影响:Rancher 2.5.9之前版本,Rancher 2.4.16之前版本。
CVSS Information
N/A
Vulnerability Type
N/A