CVE-2023-22650

Source
https://cve.org/CVERecord?id=CVE-2023-22650
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22650.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-22650
Aliases
Published
2024-10-16T09:15:02.957Z
Modified
2026-04-10T04:55:26.177688Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22650.json"