Skip to content

[GHSA-mq23-vvg7-xfm4] Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login#5654

Merged
advisory-database[bot] merged 1 commit into
github:AnonyICSE26/advisory-improvement-5654from
AnonySE26:AnonyICSE26-patch-20
May 27, 2025
Merged

[GHSA-mq23-vvg7-xfm4] Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login#5654
advisory-database[bot] merged 1 commit into
github:AnonyICSE26/advisory-improvement-5654from
AnonySE26:AnonyICSE26-patch-20

Conversation

@AnonySE26

Copy link
Copy Markdown

Updates:

  • References

Comments:
Per the v2.8.13 release notes https://github.com/rancher/rancher/releases?page=7 (“The User ID required for configuring SAML providers is now stored inside a signed JSON Web Token (JWT), ensuring it is securely protected against tampering. For more information, see CVE-2025-23389 and #48964.”), add pull request #48964 and the corresponding patch commit f36b896a99441985a1658e1b8c504d77e52fee4f

@AnonySE26 AnonySE26 changed the title [date GHSA-mq23-vvg7-xfm4] Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login [GHSA-mq23-vvg7-xfm4] Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login May 24, 2025
@github-actions github-actions Bot changed the base branch from main to AnonyICSE26/advisory-improvement-5654 May 24, 2025 07:58
@advisory-database advisory-database Bot merged commit 5b92ca3 into github:AnonyICSE26/advisory-improvement-5654 May 27, 2025
3 checks passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @AnonyICSE26! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant