在 Candlepin 中发现了一个漏洞。中央授权过滤器在多个带有 @Verify 注解的参数中,只要其中任意一个可访问就错误地授予了访问权限,而不是要求所有经过验证的实体都必须可访问。具备较低权限的已认证攻击者,如果能够访问第一个引用的对象,就可以绕过对后续对象的授权检查。当目标资源标识符已知时,这可能导致未经授权地披露消费者信息,以及未经授权地修改权益和相关订阅资源,包括跨组织的情况。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
| CVE-2026-103870 | 5.0 MEDIUM | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
No comments yet