Vulnerability record · CVE-2023-22651 · published 4 May 2023
CVE-2023-22651: Suse rancher improper privilege management vulnerability
Suse · Rancher
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.
Description
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22651 | Issue TrackingVendor Advisory |
| https://github.com/rancher/rancher/security/advisories/GHSA-6m9f-pj6w-w87g | MitigationThird Party Advisory |
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22651 | Issue TrackingVendor Advisory |
| https://github.com/rancher/rancher/security/advisories/GHSA-6m9f-pj6w-w87g | MitigationThird Party Advisory |
Track CVE-2023-22651 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22651), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.