pulp project pulp是pulp project团队开源的一个软件包管理平台。 Pulp Project Pulp存在路径遍历漏洞,该漏洞源于relative_path_validator函数仅验证内容路径不以“/”开头,但未能阻止路径中的目录遍历序列(如“../”),经身份验证的管理员可在FilesystemExport操作期间构造包含嵌入遍历序列的relative_path,将用户控制的上传文件写入Pulp服务用户可写的任意位置,可能导致服务被入侵或进一步系统利用。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:3.49.63-2.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:3.49.63-2.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:3.49.63-2.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el10
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.49.39-2.el8pc ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.49.39-2.el8pc ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.49.39-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.49.39-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.63.21-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.63.21-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.73.30-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.73.30-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.85.15-5.el9pc ~ * |
cpe:/a:redhat:satellite:6.19::el9
|
|
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.85.15-5.el9pc ~ * |
cpe:/a:redhat:satellite:6.19::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1783979593 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1783919521 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Update Infrastructure 4 for Cloud Providers | - |
cpe:/a:redhat:rhui:4::el8
|
|
| Red Hat | Red Hat Update Infrastructure 5 | - |
cpe:/a:redhat:rhui:5::el9
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-16242 | 9.4 CRITICAL | OpenShift HyperShift 授权问题漏洞 |
| CVE-2026-64612 | 7.5 HIGH | OpenPrinting libcupsfilters 异常处理不当漏洞 |
| CVE-2026-12080 | 7.3 HIGH | QEMU 后置链接漏洞 |
| CVE-2026-15813 | 6.5 MEDIUM | Kronosnet 缓冲区错误漏洞 |
| CVE-2026-16277 | 6.5 MEDIUM | Red Hat Enterprise Linux 10 缓冲区错误漏洞 |
| CVE-2026-15588 | 5.3 MEDIUM | GNOME GLib 资源管理错误漏洞 |
| CVE-2026-16254 | 4.3 MEDIUM | QUAY Claircore 缓冲区错误漏洞 |
暂无评论