Description
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
Scores
CVSS v3
9.9
EPSS
0.0020
EPSS Percentile
41.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-922
Status
published
Products (3)
rancher/rke
1.4.18 - 1.4.19Go
SUSE/rke
1.4.18 - 1.4.19
SUSE/rke
1.5.9 - 1.5.10
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026