This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6275 | A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3. |
Github GHSA |
GHSA-mq23-vvg7-xfm4 | Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login |
Fri, 11 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3. | |
| Title | Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-26T18:28:27.054Z
Reserved: 2025-01-15T12:39:03.324Z
Link: CVE-2025-23389
Updated: 2025-04-11T14:33:32.973Z
Status : Deferred
Published: 2025-04-11T11:15:42.620
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-23389
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:17Z
EUVD
Github GHSA