Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/rancher/rke2
  4. ›
  5. GHSA-x7xj-jvwp-97rv

GHSA-x7xj-jvwp-97rv: RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists

October 25, 2024

A vulnerability has been identified whereby RKE2 deployments in Windows nodes have weak Access Control Lists (ACL), allowing BUILTIN\Users or NT AUTHORITY\Authenticated Users to view or edit sensitive files which could lead to privilege escalation. This vulnerability is exclusive to RKE2 in Windows environments. Linux environments are not affected by it. Please consult the associated MITRE ATT&CK - Technique - Exploitation for Privilege Escalation for further information about this category of attack.

References

  • cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32197
  • github.com/advisories/GHSA-x7xj-jvwp-97rv
  • github.com/rancher/rancher/security/advisories/GHSA-7h8m-pvw3-5gh4
  • github.com/rancher/rke2
  • github.com/rancher/rke2/security/advisories/GHSA-x7xj-jvwp-97rv

Code Behaviors & Features

Detect and mitigate GHSA-x7xj-jvwp-97rv with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.27.0 before 1.27.15, all versions starting from 1.28.0 before 1.28.11, all versions starting from 1.29.0 before 1.29.6, all versions starting from 1.30.0 before 1.30.2

Fixed versions

  • 1.27.15
  • 1.28.11
  • 1.29.6
  • 1.30.2

Solution

Upgrade to versions 1.27.15, 1.28.11, 1.29.6, 1.30.2 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-269: Improper Privilege Management
  • CWE-732: Incorrect Permission Assignment for Critical Resource

Source file

go/github.com/rancher/rke2/GHSA-x7xj-jvwp-97rv.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:56 +0000.