在 Source-to-Image(S2I)工具中发现了一个漏洞。在解压归档文件时,该应用程序未能正确清理指向绝对文件路径的符号链接。攻击者可以通过提供一个恶意构建器镜像,在其中嵌入指向提取目录之外的链接,从而利用此漏洞。这使得攻击者能够绕过沙箱限制,可能导致在主机系统上发生未经授权的信息泄露或文件修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | OpenShift Serverless | - |
cpe:/a:redhat:serverless:1
|
|
| Red Hat | OpenShift Serverless | - |
cpe:/a:redhat:serverless:1
|
|
| Red Hat | OpenShift Serverless | - |
cpe:/a:redhat:serverless:1
|
|
| Red Hat | OpenShift Source-to-Image (S2I) | - |
cpe:/a:redhat:source_to_image:1
|
|
| Red Hat | OpenShift Source-to-Image (S2I) | - |
cpe:/a:redhat:source_to_image:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat Web Terminal | - |
cpe:/a:redhat:webterminal:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106471 | 8.1 HIGH | Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult |
| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-106064 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
| CVE-2026-107169 | 6.2 MEDIUM | M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
| CVE-2026-107167 | 6.2 MEDIUM | M17n-lib: heap use-after-free write in re_init_ic() |
| CVE-2026-107168 | 6.2 MEDIUM | M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() |
| CVE-2026-107151 | 5.9 MEDIUM | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated request |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
| CVE-2026-103870 | 5.0 MEDIUM | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
| CVE-2026-107170 | 2.9 LOW | M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
No comments yet