CVE-2023-32191: Suse Rke

Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.

Affected products

  • Suse Rke: from 1.4.18, before 1.4.19 (fixed in 1.4.19); from 1.5.9, before 1.5.10 (fixed in 1.5.10)

Published 2024-10-16. Last modified 2026-06-17.