Executive brief
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login in github.com/rancher/rancher
Affected products
- Go github.com/rancher/rancher
Junglewise Threat Intelligence
CVE-2025-23389 · Severity: low · CVSS 3.1 · Published 2025-03-03
Technologies: github.com/rancher/rancher (Go). Vendors: Go.
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login in github.com/rancher/rancher