CVE-2023-32191
When RKE provisions a cluster, it stores the cluster state in a configmap called full-cluster-state inside the kube-system namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32191.json, https://github.com/rancher/rke/security/advisories/GHSA-6gr4-52w6-vmqx, https://nvd.nist.gov/vuln/detail/CVE-2023-32191, https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32191