This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9310 | A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4. |
Github GHSA |
GHSA-8p83-cpfg-fj3g | Rancher: Restricted Administrator can change Administrator's passwords |
Fri, 11 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4. | |
| Title | Rancher: Restricted Administrator can change Administrator's passwords | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-26T18:28:27.368Z
Reserved: 2025-01-15T12:39:03.324Z
Link: CVE-2025-23391
Updated: 2025-04-11T14:34:11.612Z
Status : Deferred
Published: 2025-04-11T11:15:42.747
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-23391
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:17Z
EUVD
Github GHSA