CVE-2023-22650 - CVE House
Back to Database
Status published High CVE-2023-22650

Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider

Vulnerability Description

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-22650

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rancher
Vulnerable Versions:
2.7.0, 2.8.0

Timeline

Official Publish: October 16th, 2024
Last Modified: October 16th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)