Skip to content

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-9ghh-mmcq-8phc #2931

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-9ghh-mmcq-8phc references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

A vulnerability has been identified in which Rancher does not automatically
clean up a user which has been deleted from the configured authentication
provider (AP). This characteristic also applies to disabled or revoked users,
Rancher will not reflect these modifications which may leave the user’s tokens
still usable.

An AP must be enabled to be affected by this, as the built-in User Management
feature is not affected by this vulnerability. This issue may lead to an
adversary gaining unauthorized access, as the user’s access privileges may
still be active within Rancher even ...

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      non_go_versions:
        - introduced: 2.7.0
          fixed: 2.7.14
        - introduced: 2.8.0
          fixed: 2.8.5
      vulnerable_at: 1.6.30
      packages:
        - package: github.com/rancher/rancher
summary: |-
    Rancher does not automatically clean up a user deleted or disabled from the
    configured Authentication Provider in github.com/rancher/rancher
cves:
    - CVE-2023-22650
ghsas:
    - GHSA-9ghh-mmcq-8phc
references:
    - advisory: https://github.com/advisories/GHSA-9ghh-mmcq-8phc
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-9ghh-mmcq-8phc
source:
    id: GHSA-9ghh-mmcq-8phc
    created: 2024-06-17T23:01:15.933991616Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions