Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/rancher/rancher: GHSA-9ghh-mmcq-8phc #2931

Closed
GoVulnBot opened this issue Jun 17, 2024 · 2 comments
Assignees
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-9ghh-mmcq-8phc references a vulnerability in the following Go modules:

Module
github.com/rancher/rancher

Description:

Impact

A vulnerability has been identified in which Rancher does not automatically
clean up a user which has been deleted from the configured authentication
provider (AP). This characteristic also applies to disabled or revoked users,
Rancher will not reflect these modifications which may leave the user’s tokens
still usable.

An AP must be enabled to be affected by this, as the built-in User Management
feature is not affected by this vulnerability. This issue may lead to an
adversary gaining unauthorized access, as the user’s access privileges may
still be active within Rancher even ...

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/rancher/rancher
      non_go_versions:
        - introduced: 2.7.0
          fixed: 2.7.14
        - introduced: 2.8.0
          fixed: 2.8.5
      vulnerable_at: 1.6.30
      packages:
        - package: github.com/rancher/rancher
summary: |-
    Rancher does not automatically clean up a user deleted or disabled from the
    configured Authentication Provider in github.com/rancher/rancher
cves:
    - CVE-2023-22650
ghsas:
    - GHSA-9ghh-mmcq-8phc
references:
    - advisory: https://github.com/advisories/GHSA-9ghh-mmcq-8phc
    - advisory: https://github.com/rancher/rancher/security/advisories/GHSA-9ghh-mmcq-8phc
source:
    id: GHSA-9ghh-mmcq-8phc
    created: 2024-06-17T23:01:15.933991616Z
review_status: UNREVIEWED

@tatianab tatianab self-assigned this Jun 25, 2024
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/594901 mentions this issue: data/reports: add 18 unreviewed reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/595636 mentions this issue: data/reports: add 15 unreviewed reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants