← back
CVE-2022-21953highCWE-862

Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.4epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected products
SUSE · Rancher