Junglewise Threat Intelligence

CVE-2025-23389: GO-2025-3490 - Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login in github.com/rancher/r

CVE-2025-23389 · Severity: low · CVSS 3.1 · Published 2025-03-03

Technologies: github.com/rancher/rancher (Go). Vendors: Go.

Executive brief

Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login in github.com/rancher/rancher

Affected products

  • Go github.com/rancher/rancher

Related threats