Database/Container, Kubernetes & orchestration
Rancher: Standard users manipulate Kubernetes secrets in the local (management) cluster
CVSS 9.9CVE-2023-22647Container, Kubernetes & orchestrationcurated
Impact
Standard users manipulate Kubernetes secrets in the local (management) cluster
Who can reach it
Any authenticated Rancher user
What to do
Upgrade Rancher; audit local-cluster secrets
References
Related entries
- Rancher: Update-logic failure misconfigures Rancher's admission webhook, disabling the validation that enforcesCVE-2023-22651 · RancherCritical
- Rancher: SAML assertion replay: the ACS handler does not enforce one-time use, so a captured assertion logsCVE-2026-44946 · RancherCritical
- Rancher: Anyone who can create role template bindings escalates privileges cluster-wideCVE-2022-31247 · RancherCritical
- Rancher: Incorrectly applied authorization check lets a namespace be moved into a different projectCVE-2020-10676 · RancherHigh
- Rancher: Sensitive data leaked into Rancher audit logsCVE-2023-22649 · RancherHigh
- Rancher: CLI login with -skip-verify and no --cacert silently accepts any certificateCVE-2025-67601 · RancherHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.