CVE-2023-32199
MEDIUMDescription
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
Is your site exposed to CVE-2023-32199?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2023-32199? +
How severe is CVE-2023-32199? +
How do I check if I'm vulnerable to CVE-2023-32199? +
Related Vulnerabilities
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
SystemUI has an incorrect component protection setting, which allows access to specific information.