Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/rancher/rancher
  4. ›
  5. CVE-2023-22648

CVE-2023-22648: Rancher's Azure AD permission changes are not reflected on active sessions

March 3, 2026

A bug has been identified in which permission changes in Azure AD are not reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it.

References

  • bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22648
  • github.com/advisories/GHSA-vf6j-6739-78m8
  • github.com/rancher/rancher
  • github.com/rancher/rancher/security/advisories/GHSA-vf6j-6739-78m8
  • nvd.nist.gov/vuln/detail/CVE-2023-22648

Code Behaviors & Features

Detect and mitigate CVE-2023-22648 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.6.7 before 2.6.13, all versions starting from 2.7.0 before 2.7.4

Fixed versions

  • 2.6.13
  • 2.7.4

Solution

Upgrade to versions 2.6.13, 2.7.4 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-269: Improper Privilege Management
  • CWE-271: Privilege Dropping / Lowering Errors
  • CWE-384: Session Fixation

Source file

go/github.com/rancher/rancher/CVE-2023-22648.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 12 May 2026 12:26:20 +0000.