VYPR

Rke

by Rancher

Source repositories

CVEs (1)

  • CVE-2023-32191CriOct 16, 2024
    risk 0.57cvss 9.9epss 0.01

    When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.