permissions for core namespaces. This can lead to someone being capable
of accessing, creating, updating, or deleting a namespace in the
project.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0611 | A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project. |
Github GHSA |
GHSA-c85r-fwc7-45vc | Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core' |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rancher
Rancher rancher |
|
| CPEs | cpe:2.3:a:rancher:rancher:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rancher
Rancher rancher |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project. | |
| Title | Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core' | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-10-16T17:25:32.070Z
Reserved: 2023-05-04T08:30:59.322Z
Link: CVE-2023-32194
Updated: 2024-10-16T16:04:57.754Z
Status : Deferred
Published: 2024-10-16T13:15:12.787
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-32194
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA