CVE-2024-58260

7.6

SUSE · Rancher Manager

A missing server-side validation in the Rancher Manager .username field allows authenticated users with specific permissions to cause a denial of access for targeted accounts.

Executive summary

A critical authorization flaw in Rancher Manager allows authenticated users to trigger a denial of service against other accounts, necessitating immediate patching.

Vulnerability

This vulnerability is an incorrect authorization flaw (CWE-863) where the system fails to validate the .username field, allowing a user who already possesses update permissions on other User resources to disrupt access for other accounts.

Business impact

The vulnerability poses a significant risk to operational continuity by enabling unauthorized users to perform denial of service attacks against other accounts. While the CVSS score of 7.6 indicates a high severity, the requirement for existing administrative or update privileges limits the immediate attack surface to internal or compromised accounts. Successful exploitation results in account lockout or service disruption, which can hinder administrative operations and impact infrastructure management.

Remediation

Immediate Action: Upgrade Rancher Manager to version 2.12.2, 2.11.6, 2.10.10, or 2.9.12, depending on the currently deployed release branch.

Proactive Monitoring: Review audit logs for suspicious modification attempts on User resources, specifically tracking unauthorized changes to the .username field.

Compensating Controls: Restrict administrative access to the Rancher management interface to trusted personnel only, ensuring the principle of least privilege is strictly enforced for all user accounts.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Organizations should prioritize the update of Rancher Manager instances to the specified fixed versions to eliminate this authorization vulnerability. Given the potential for service disruption, applying these patches during the next scheduled maintenance window is recommended to ensure stability and secure management operations.

More SUSE CVEs

Sources