PT-2026-99921 · Suse · Rancher Fleet+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SUSE Rancher Fleet versions 0.16 through 0.16.1
SUSE Rancher Fleet versions 0.15 through 0.15.6
SUSE Rancher Fleet versions 0.14 through 0.14.10
Description
An issue exists in Rancher Manager where the Fleet agent utilizes its own cluster-admin credentials to write resources to downstream clusters instead of using the ServiceAccount pinned to the deployment. In multi-tenancy environments where different tenants, such as privileged or untrusted teams within the same organization, share the same downstream clusters, this could result in the overwriting of configuration files.
Recommendations
Update SUSE Rancher Fleet version 0.16 to 0.16.2.
Update SUSE Rancher Fleet version 0.15 to 0.15.7.
Update SUSE Rancher Fleet version 0.14 to 0.14.11.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher Fleet
Rancher Manager