CVE-2023-32191
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.14%
- CWE
- CWE-922
- Published
- 2024-10-16
- Last modified
- 2026-03-13
Affected products
- SUSE rke
- SUSE rke
Weakness type
Related vulnerabilities
- CVE-2024-7569 — An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows a
- CVE-2022-0724 — Insecure Storage of Sensitive Information in microweber/microweber
- CVE-2024-3501 — Exposure of Sensitive Information in lunary-ai/lunary
- CVE-2024-10943 — FactoryTalk® Updater Authentication Bypass
- CVE-2025-10971 — Insecure Storage of Sensitive Information
- CVE-2023-43634 — Config Partition Not Protected by Measured Boot
- CVE-2023-43633 — Debug Functions Unlockable Without Triggering Measured Boot
- CVE-2023-43631 — SSH as Root Unlockable Without Triggering Measured Boot