Red Hat Red Hat Advanced Cluster Security是美国Red Hat公司的一款集群安全防护软件。 Red Hat Advanced Cluster Security 4版本存在输入验证错误漏洞,该漏洞源于处理Kubernetes Deployments时对openshift.io/encoded-deployment-config标签处理不当,可能导致绕过部署时策略检测和执行可见性,破坏违规报告和合规关联。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Security 4 | any |
affected |
any |
affected | ||
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Security 4 | - |
cpe:/a:redhat:advanced_cluster_security:4
|
|
| Red Hat | Red Hat Advanced Cluster Security 4 | - |
cpe:/a:redhat:advanced_cluster_security:4
|
|
| Red Hat | Red Hat Advanced Cluster Security 4 | - |
cpe:/a:redhat:advanced_cluster_security:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18141 | 8.2 HIGH | Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http he |
| CVE-2026-15722 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_ |
| CVE-2026-11770 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check |
| CVE-2026-18215 | 6.8 MEDIUM | Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses co |
| CVE-2026-18214 | 6.8 MEDIUM | Keycloak-services: keycloak-services: google external access-token exchange bypasses hoste |
| CVE-2026-18208 | 6.5 MEDIUM | Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks s |
| CVE-2026-18203 | 6.5 MEDIUM | Keycloak-services: keycloak-services: group policy extendchildren matches sibling group pa |
| CVE-2026-16105 | 4.9 MEDIUM | Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresou |
| CVE-2026-18218 | 4.2 MEDIUM | Keycloak-services: keycloak-services: client not-before revocation ignored when realm not- |
| CVE-2026-18211 | 4.2 MEDIUM | Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefi |
| CVE-2026-18206 | 3.7 LOW | Keycloak-services: keycloak-services: client policy source-host wildcard domain matching b |
| CVE-2026-18217 | 3.4 LOW | Keycloak-services: keycloak-services: saml http-redirect binding response preserves query |
| CVE-2026-18209 | 3.4 LOW | Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter |
No comments yet