{"id":"GHSA-w3x4-9854-95x8","summary":"Rancher Access Control Vulnerability","details":"Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.","aliases":["CVE-2017-7297","GO-2023-1973"],"modified":"2024-08-20T20:58:55.480573Z","published":"2022-05-13T01:02:31Z","database_specific":{"cwe_ids":[],"github_reviewed_at":"2023-07-25T21:57:14Z","github_reviewed":true,"nvd_published_at":"2017-03-29T00:59:00Z","severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7297"},{"type":"WEB","url":"https://github.com/rancher/rancher/issues/8296"},{"type":"PACKAGE","url":"https://github.com/rancher/rancher"},{"type":"WEB","url":"https://web.archive.org/web/20200227181556/http://www.securityfocus.com/bid/97180"}],"affected":[{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"fixed":"1.5.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json"}},{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.4.0"},{"fixed":"1.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json"}},{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.0"},{"fixed":"1.3.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json"}},{"package":{"name":"github.com/rancher/rancher","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/rancher"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.2.0"},{"fixed":"1.2.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w3x4-9854-95x8/GHSA-w3x4-9854-95x8.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}