Listen to this Post
How the CVE Works:
In Rancher Manager, assigning a user a custom GlobalRole with wildcard (“) permissions for all resources and non-resource URLs triggers the automatic creation of a corresponding ClusterRoleBinding on every managed cluster. This binding links the user to the built-in `cluster-admin` ClusterRole, granting them full administrative access. The vulnerability, an improper access control flaw, occurs when this custom GlobalRole or its associated GlobalRoleBinding is deleted. The deletion process fails to clean up the downstream ClusterRoleBindings created on the managed clusters. These orphaned bindings persist, allowing the user to retain full cluster-admin access across all clusters even after their central administrative permissions have been ostensibly revoked. This creates a significant privilege escalation and persistence vector, undermining user de-provisioning and security policies.
DailyCVE Form:
Platform: Rancher Manager
Version: < v2.11.7, < v2.12.3
Vulnerability: Improper Access Control
Severity: Critical
date: 2023
Prediction: Patch Available
What Undercode Say:
`kubectl get clusterrolebinding -o jsonpath='{range .items[?(@.metadata.annotations.authz\.cluster\.cattle\.io/admin-globalrole-missing==”true”)]}{.metadata.name}{“\n”}{end}’`
`kubectl delete clusterrolebinding `
How Exploit:
Delete admin GlobalRole.
User retains cluster access.
Protection from this CVE
Upgrade to patched versions.
Manually delete orphaned bindings.
Impact:
Persistent cluster admin access.
Bypasses account removal.
Privilege escalation.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

