Medium severity6.6GHSA Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2023-32196
CVE-2023-32196
Description
A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.7.0, < 2.7.14 | 2.7.14 |
github.com/rancher/rancherGo | >= 2.8.0, < 2.8.5 | 2.8.5 |
Affected products
5- osv-coords4 versionspkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester-webhookpkg:golang/github.com/rancher/rancher
< 1.8.1-r1+ 3 more
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r0
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: >= 2.7.0, < 2.7.14
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.