When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/rancher/rke(Go) | 1.4.18 | 1.4.19 | N/A |
| github.com/rancher/rke(Go) | 1.5.9 | 1.5.10 | N/A |
CVSS Metrics