<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:40:41.979273+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-225029</id>
    <title>EUVD-2026-225029</title>
    <updated>2026-10-03T09:40:41.982468+00:00</updated>
    <content>EUVD-2026-225029</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-225029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21953</id>
    <title>fkie_cve-2022-21953</title>
    <updated>2026-10-03T09:40:41.982499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g25r-gvq3-wrq7</id>
    <title>GHSA-g25r-gvq3-wrq7 — Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster</title>
    <updated>2026-10-03T09:40:41.982530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact</p>
<p>An issue was discovered in Rancher where an authorization logic flaw allows an authenticated user on any downstream cluster to (1) open a shell pod in the Rancher `local` cluster and (2) have limited `kubectl` access to it. The expected behavior is that a user does not have such access in the Rancher `local` cluster unless explicitly granted.</p>
<p>This issue does not allow the user to escalate privileges in the `local` cluster directly (this would require another vulnerability to be exploited).</p>
<p>The security issue happens in two different ways:</p>
<p>1. Shell pod access - This is when a user opens a shell pod in the Rancher UI to a downstream cluster that the user has permission to access. The web request can be intercepted using the browser's web inspector/network console or a proxy tool to change the shell's destination to the Rancher `local` cluster instead of the desired downstream cluster.</p>
<p>- This flaw cannot be exploited to access a downstream cluster that the user has no permissions to.</p>
<p>- The shell pod runs with a limited non-root user, reducing the severity of this issue. However, even as a non-root user, it is still possible download and run binaries inside the shell pod.</p>
<p>- The blast radius of this issue can increase based on the configuration of the `local` cluster. For example:</p>
<p>- If the `local` cluster has unlimited network access, e.g. to the Internet, the user can open a reverse network connection to the shell pod.</p>
<p>- Or access the clo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g25r-gvq3-wrq7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21953</id>
    <title>gsd-2022-21953</title>
    <updated>2026-10-03T09:40:41.982582+00:00</updated>
    <content>gsd-2022-21953</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197</id>
    <title>WID-SEC-W-2023-0197 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:40:41.982596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, seine Rechte zu erweitern und Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197"/>
  </entry>
</feed>
