Miggo Logo

CVE-2023-22650: Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.39363%
Published
6/17/2024
Updated
10/16/2024
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/rancher/ranchergo>= 2.7.0, < 2.7.142.7.14
github.com/rancher/ranchergo>= 2.8.0, < 2.8.52.8.5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t * vuln*r**ility **s ***n i**nti*i** in w*i** R*n***r *o*s not *utom*ti**lly *l**n up * us*r w*i** **s ***n **l*t** *rom t** *on*i*ur** *ut**nti**tion provi**r (*P). T*is ***r**t*risti* *lso *ppli*s to *is**l** or r*vok** us*rs, R*n***r wi

Reasoning

No *n*lysis *v*il**l*