// For flags

CVE-2022-31247

Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.6.7; Rancher versions prior to 2.5.16.

Una vulnerabilidad de autorización inapropiada en SUSE Rancher, permite a cualquier usuario que tenga permisos para crear/editar enlaces de plantillas de roles de clúster o enlaces de plantillas de roles de proyecto (como propietario de clúster, administrar miembros de clúster, propietario de proyecto y administrar miembros de proyecto) obtener permiso de propietario en otro proyecto en el mismo clúster o en otro proyecto en un clúster descendente diferente. Este problema afecta a: SUSE Rancher versiones anteriores a 2.6.7; Rancher versiones anteriores a 2.5.16

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-20 CVE Reserved
  • 2022-09-07 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-285: Improper Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Suse
Search vendor "Suse"
Rancher
Search vendor "Suse" for product "Rancher"
>= 2.5.0 < 2.5.16
Search vendor "Suse" for product "Rancher" and version " >= 2.5.0 < 2.5.16"
-
Affected
Suse
Search vendor "Suse"
Rancher
Search vendor "Suse" for product "Rancher"
>= 2.6.0 < 2.6.7
Search vendor "Suse" for product "Rancher" and version " >= 2.6.0 < 2.6.7"
-
Affected