
Cloud Vulnerability DB
A community-led vulnerabilities database
A Missing Authorization vulnerability (CVE-2022-21953) was discovered in SUSE Rancher that allows authenticated users to create unauthorized shell pods and gain kubectl access in the local cluster. This vulnerability affects SUSE Rancher versions prior to 2.5.17, prior to 2.6.10, and prior to 2.7.1 (MITRE CVE, NVD).
The vulnerability stems from a missing authorization check in SUSE Rancher that allows authenticated users to bypass access controls. This security flaw enables users to create shell pods and obtain kubectl access in the local cluster, even without proper authorization to do so (SUSE Bugzilla).
The successful exploitation of this vulnerability could allow authenticated users to gain unauthorized access to the local cluster through shell pods and kubectl commands, potentially compromising the security and integrity of the Kubernetes environment (NVD).
The vulnerability requires authentication for exploitation, meaning an attacker must first have valid credentials to the Rancher system. However, once authenticated, the attacker can bypass intended access restrictions to gain unauthorized cluster access (MITRE CVE).
Users should upgrade to SUSE Rancher version 2.5.17, 2.6.10, or 2.7.1 or later, depending on their current version stream. These versions contain the necessary security fixes to address the vulnerability (SUSE Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."