CVE-2023-32199
MEDIUMDescription
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
Is your site exposed to CVE-2023-32199?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2023-32199? +
How severe is CVE-2023-32199? +
How do I check if I'm vulnerable to CVE-2023-32199? +
Related Vulnerabilities
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
SystemUI has an incorrect component protection setting, which allows access to specific information.
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …