在 pulp-rpm 发布分布树(distribution tree)时存在一个缺陷。系统会使用 文件中的 addon 和 variant ID 作为目录名。具有同步或上传该树权限的用户可以导致发布任务在工作区之外创建新目录,并以 Pulp 工作进程用户的身份将树的仓库元数据和包写入这些目录中。已存在的文件或目录不会被替换。此缺陷不会导致数据泄露,也不会导致服务中断。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Update Infrastructure 4 for Cloud Providers | - |
cpe:/a:redhat:rhui:4::el8
|
|
| Red Hat | Red Hat Update Infrastructure 4 for Cloud Providers | - |
cpe:/a:redhat:rhui:4::el8
|
|
| Red Hat | Red Hat Update Infrastructure 5 | - |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | - |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | - |
cpe:/a:redhat:rhui:5::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106471 | 8.1 HIGH | Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult |
| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
No comments yet