CyberRota Analysis
AI-GeneratedA vulnerability in Rancher Manager allows the Fleet agent to utilize its own cluster-admin credentials to write resources to downstream clusters, bypassing the intended ServiceAccount restrictions. This poses a significant risk in multi-tenancy environments, as it could enable unauthorized access and overwrite configuration files across shared clusters. Organizations using affected versions of SUSE Rancher Fleet, particularly those with multiple teams sharing clusters, should prioritize addressing this issue to mitigate potential security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
Related CVEs
Other vulnerabilities affecting the same vendor(s)