Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rancher | Suse | 2.13.0 (including) | 2.13.6 (excluding) |
| Rancher | Suse | 2.14.0 (including) | 2.14.2 (excluding) |