Red Hat OpenShift是美国红帽(Red Hat)公司的一款平台即服务(PaaS)云计算平台,它支持构建、测试、部署和运行应用程序。 Red Hat OpenShift Update Service存在安全漏洞,该漏洞源于构建过程中/etc/passwd文件被设置为组可写权限,可能导致攻击者在容器内获得完整root权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32589 | 7.4 HIGH | Mirror-registry: quay: insecure direct object reference in blobupload |
| CVE-2026-32590 | 7.1 HIGH | Mirror-registry: remote code execution using pickle deserialization |
| CVE-2026-2377 | 6.5 MEDIUM | Mirror-registry: quay: quay: server-side request forgery via log export functionality |
| CVE-2025-57851 | 6.4 MEDIUM | Mce: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-57847 | 6.4 MEDIUM | Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd |
| CVE-2025-57853 | 6.4 MEDIUM | Web-terminal: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-58713 | 6.4 MEDIUM | Rhpam: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-14243 | 5.3 MEDIUM | Mirror-registry: openshift mirror registry: user enumeration via authentication error mess |
| CVE-2026-32591 | 5.2 MEDIUM | Mirror-registry: quay: server-side request forgery in proxy cache upstream registry config |
No comments yet