在 gvproxy 中发现了一个路径遍历漏洞,gvproxy 是 gvisor-tap-vsock 包提供的网络转发器。未经身份验证的 /services/forwarder/expose 端点没有对用户提供的套接字路径进行验证,从而允许攻击者删除主机系统上的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Podman Desktop | - |
cpe:/a:redhat:podman_desktop:1
|
|
| Red Hat | Red Hat Certification Program for Red Hat Enterprise Linux 9 | - |
cpe:/a:redhat:certifications:9
|
|
| Red Hat | Red Hat Edge Manager 1 | - |
cpe:/a:redhat:edge_manager:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenStack Platform 18.0 | - |
cpe:/a:redhat:openstack:18.0
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107889 | 5.5 MEDIUM | Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass |
| CVE-2026-107655 | 4.0 MEDIUM | Cups: null pointer dereference via embedded job ticket comments allows remote denial of se |
No comments yet