A vulnerability has been identified within Rancher
Manager, where after removing a custom GlobalRole that gives
administrative access or the corresponding binding, the user still
retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
References
Configurations
No configuration.
History
29 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-29 15:15
Updated : 2025-10-30 15:03
NVD link : CVE-2023-32199
Mitre link : CVE-2023-32199
CVE.ORG link : CVE-2023-32199
JSON object : View
Products Affected
No product.
CWE
CWE-281
Improper Preservation of Permissions
