在 flatpak-builder 中发现了一个漏洞。该漏洞允许攻击者通过诱使用户或持续集成(CI)系统处理一个精心构造的构建清单,从而导致信息泄露。通过在源码下载定义中指定本地文件统一资源标识符(URIs),构建工具能够绕过目录隔离检查。结果是,构建进程可访问的敏感主机文件可能被读取并包含到构建产物中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello docker tags repositories api cross-organization authorization byp |
No comments yet