在 cluster-samples-operator 中发现了一个缺陷。位于 openshift-config 命名空间中的 RBAC Role coreos-pull-secret-reader 对所有 Secret 资源授予了 get、list 和 watch 权限,且未对资源名称(resourceNames)进行限制。然而,该 Operator 实际上仅需访问 pull-secret 这一个 Secret。如果 samples-operator Pod 或其服务账户令牌通过其他漏洞被攻陷,攻击者便可读取 op
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106471 | 8.1 HIGH | Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult |
| CVE-2026-107161 | 7.5 HIGH | Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server |
| CVE-2026-103868 | 6.5 MEDIUM | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-103869 | 6.5 MEDIUM | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-107121 | 6.5 MEDIUM | Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg |
| CVE-2026-107174 | 6.4 MEDIUM | Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extr |
| CVE-2026-106067 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in hot color filter on oversized image |
| CVE-2026-106064 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
| CVE-2026-106065 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions |
| CVE-2026-106066 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions |
| CVE-2026-107168 | 6.2 MEDIUM | M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() |
| CVE-2026-107167 | 6.2 MEDIUM | M17n-lib: heap use-after-free write in re_init_ic() |
| CVE-2026-107169 | 6.2 MEDIUM | M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
| CVE-2026-107151 | 5.9 MEDIUM | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated request |
| CVE-2026-106061 | 5.5 MEDIUM | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
| CVE-2026-103870 | 5.0 MEDIUM | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
| CVE-2026-107170 | 2.9 LOW | M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
No comments yet