QID 997161
Date Published: 2024-02-09
QID 997161: GO (Go) Security Update for github.com/rancher/rancher (GHSA-c85r-fwc7-45vc)
A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project. This includes reading or updating a namespace in the project so that it is available in other projects in which the user has the "manage-namespaces" permission or updating another namespace in which the user has normal "update" permissions to be moved into the project.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c85r-fwc7-45vc for updates and patch information.
Vendor References
- GHSA-c85r-fwc7-45vc -
github.com/advisories/GHSA-c85r-fwc7-45vc
CVEs related to QID 997161
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c85r-fwc7-45vc | github.com/rancher/rancher |
|