发现 HyperShift 算子(operator)存在一个安全缺陷。该算子会直接将用户提供的 Kubernetes 配置(kubeconfig)密钥复制到权限较高的控制平面命名空间中,而未进行充分的验证或清理。拥有集群和密钥创建权限的经过身份验证的用户,可以通过提供包含未授权可执行插件的配置来利用此漏洞。当下游控制器消费该配置时,攻击者即可在控制平面中实现任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71299 | 6.5 MEDIUM | Maestro: maestro: rest api write endpoints registered without authentication middleware |
| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-71298 | 6.4 MEDIUM | Maestro: sql identifier injection via properties.* search filter and orderby field |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-105447 | 5.5 MEDIUM | Quay: quay: global read-only superuser can access build trigger write credentials |
| CVE-2026-104030 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-71297 | 5.4 MEDIUM | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional |
| CVE-2026-102295 | 5.4 MEDIUM | Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter |
| CVE-2026-102576 | 4.2 MEDIUM | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
| CVE-2026-104029 | 3.3 LOW | Sssd: sssd: denial of service via out-of-bounds read in autofs responder |
| CVE-2026-105326 | 2.5 LOW | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
No comments yet