CVE-2023-22650 describes a critical vulnerability in Rancher where user accounts deleted, disabled, or revoked from an external authentication provider are not automatically deprovisioned within Rancher. This oversight allows previously valid user tokens to remain active, potentially granting unauthorized access to sensitive resources. With a CVSS score of 8.8 (High), this network-exploitable flaw requires low privileges but can lead to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7.0, < 2.7.14CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.5CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.