blob: 097a1694aebd64e914a40bc9642a4101ff837bb7 [file] [log] [blame]
id: GO-2025-3586
modules:
- module: github.com/rancher/rancher
non_go_versions:
- introduced: 2.8.0
- fixed: 2.8.14
- introduced: 2.9.0
- fixed: 2.9.8
- introduced: 2.10.0
- fixed: 2.10.4
vulnerable_at: 1.6.30
summary: 'Rancher: Restricted Administrator can change Administrator''s passwords in github.com/rancher/rancher'
cves:
- CVE-2025-23391
ghsas:
- GHSA-8p83-cpfg-fj3g
references:
- advisory: https://github.com/rancher/rancher/security/advisories/GHSA-8p83-cpfg-fj3g
source:
id: GHSA-8p83-cpfg-fj3g
created: 2025-04-02T11:31:10.729499-04:00
review_status: UNREVIEWED