Database/Container, Kubernetes & orchestration
Rancher: Anyone who can create role template bindings escalates privileges cluster-wide
CVSS 9.1CVE-2022-31247Container, Kubernetes & orchestrationcurated
Impact
Anyone who can create role template bindings escalates privileges cluster-wide
Who can reach it
Cluster user with cluster-owner or project-owner rights
What to do
Upgrade Rancher; audit RoleTemplateBindings
References
Related entries
- Rancher: Incorrectly applied authorization check lets a namespace be moved into a different projectCVE-2020-10676 · RancherHigh
- Rancher: Sensitive data leaked into Rancher audit logsCVE-2023-22649 · RancherHigh
- Rancher: CLI login with -skip-verify and no --cacert silently accepts any certificateCVE-2025-67601 · RancherHigh
- Rancher: OS command injection through an untrusted Helm catalog URLCVE-2022-43758 · RancherHigh
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessCVE-2022-21953 · RancherHigh
- Rancher: restricted-admin role escalates to full adminCVE-2021-36784 · RancherHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.