CVE-2020-10676
Rancher vulnerability analysis and mitigation

Overview

CVE-2020-10676 is a security vulnerability discovered in Rancher versions 2.x before 2.6.13 and 2.7.x before 2.7.4. The vulnerability stems from an incorrectly applied authorization check that allows users who have certain access to a namespace to move that namespace to a different project (NVD, GitHub Advisory).

Technical details

The vulnerability is characterized by an authorization bypass issue where users with update privileges on a namespace can move that namespace into a project they don't have access to. After the namespace transfer is completed, their previous permissions are still preserved, which enables them to gain access to project-specific resources, such as project secrets. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The impact of this vulnerability is significant as it allows users to gain unauthorized access to project-specific resources. Additionally, resources in the moved namespace will count toward the quota limit of the new project, potentially causing availability issues. Users with roles such as Project Owner and Project Member on the source project can exploit this vulnerability, as well as users with custom roles having similar privileges (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Rancher versions 2.6.13 and 2.7.4. The patched versions include an improved RBAC mechanism that checks if the user has the correct permissions before the namespace move takes place. There is no direct mitigation besides updating Rancher to a patched version (GitHub Advisory, Rancher Release).

Additional resources


SourceThis report was generated using AI

Related Rancher vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-10676HIGH8.8
  • RancherRancher
  • github.com/rancher/rancher
NoYesDec 12, 2023
CVE-2023-22648HIGH8.8
  • RancherRancher
  • rancher
NoYesJun 01, 2023
CVE-2023-22649HIGH8.4
  • RancherRancher
  • rancher
NoYesOct 16, 2024
CVE-2022-43760HIGH8.4
  • RancherRancher
  • github.com/rancher/rancher
NoYesJun 01, 2023
CVE-2023-22647HIGH8
  • RancherRancher
  • rancher
NoYesJun 01, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management