Rancher Project Members Have Continued Access to Namespaces After Being Removed From Them
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 24, 2024
Description
Published by the National Vulnerability Database
Apr 10, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 24, 2024
Reviewed
Apr 24, 2024
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
References