NeuVector是美国NeuVector公司的一套端到端的容器安全平台。该平台包括图像漏洞管理、准入控制和容器进程/文件系统保护等功能。 NeuVector存在操作系统命令注入漏洞,该漏洞源于enforcer容器使用环境变量CLUSTER_RPC_PORT和CLUSTER_LAN_PORT生成通过popen执行的命令时未清理其值,可能导致命令注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-54470 | 8.6 HIGH | NeuVector telemetry sender is vulnerable to MITM and DoS |
| CVE-2025-54471 | 6.5 MEDIUM | NeuVector is shipping cryptographic material into its binary |
| CVE-2025-53880 | susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversa | |
| CVE-2025-53883 | spacewalk-java has various XSS issues on search page |
No comments yet