CVE-2023-32199
Análise e mitigação de vulnerabilidades

Visão geral

A vulnerability (CVE-2023-32199) was identified in Rancher Manager, affecting versions 2.12.0-2.12.3, 2.11.0-2.11.7, and versions 2.10.0 and 2.9.0. The vulnerability allows users to retain administrative access to clusters even after their custom GlobalRole or corresponding binding has been removed. This vulnerability was discovered and disclosed in October 2025 (GitHub Advisory).

Detalhes técnicos

The vulnerability specifically affects custom Global Roles that have '' on '' in '' rule for resources and '' on '*' rule for non-resource URLs. When a user is bound to a custom admin GlobalRole, a corresponding ClusterRoleBinding is created on all clusters that binds them to the cluster-admin ClusterRole. The issue occurs when such a GlobalRole or the GlobalRoleBinding is deleted, as the ClusterRoleBinding that grants cluster-admin privileges remains active. The vulnerability has been assigned a CVSS score of 4.3 (Moderate) with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L (GitHub Advisory).

Impacto

The vulnerability allows users to maintain access to clusters after their administrative privileges have been revoked through either unassignment from the custom admin global role or deletion of the role itself. This creates a security risk where users can continue to perform administrative actions on clusters despite having their permissions officially removed (GitHub Advisory).

Mitigação e soluções alternativas

The vulnerability has been patched in Rancher versions v2.12.3 and v2.11.7. The fix removes corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings are marked with the annotation 'authz.cluster.cattle.io/admin-globalrole-missing=true' and should be deleted manually. For deployments that cannot be upgraded, users are advised to manually identify and remove the orphaned ClusterRoleBindings (GitHub Advisory).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adão FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades