Rancher Manager, Improper Access Control, CVE-2023-22650 (Critical)

Listen to this Post

How the CVE Works:

In Rancher Manager, assigning a user a custom GlobalRole with wildcard (“) permissions for all resources and non-resource URLs triggers the automatic creation of a corresponding ClusterRoleBinding on every managed cluster. This binding links the user to the built-in `cluster-admin` ClusterRole, granting them full administrative access. The vulnerability, an improper access control flaw, occurs when this custom GlobalRole or its associated GlobalRoleBinding is deleted. The deletion process fails to clean up the downstream ClusterRoleBindings created on the managed clusters. These orphaned bindings persist, allowing the user to retain full cluster-admin access across all clusters even after their central administrative permissions have been ostensibly revoked. This creates a significant privilege escalation and persistence vector, undermining user de-provisioning and security policies.

DailyCVE Form:

Platform: Rancher Manager
Version: < v2.11.7, < v2.12.3
Vulnerability: Improper Access Control
Severity: Critical

date: 2023

Prediction: Patch Available

What Undercode Say:

`kubectl get clusterrolebinding -o jsonpath='{range .items[?(@.metadata.annotations.authz\.cluster\.cattle\.io/admin-globalrole-missing==”true”)]}{.metadata.name}{“\n”}{end}’`

`kubectl delete clusterrolebinding `

How Exploit:

Delete admin GlobalRole.

User retains cluster access.

Protection from this CVE

Upgrade to patched versions.

Manually delete orphaned bindings.

Impact:

Persistent cluster admin access.

Bypasses account removal.

Privilege escalation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top