In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10676.json"